OSV 1.4.0 · github-reviewed · 修改于 2020-01-08 01:20
发布时间
2020-01-08 01:20
GitHub 审查时间
2020-01-08 01:20
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/01/GHSA-f884-gm86-cg3q/GHSA-f884-gm86-cg3q.json
We have identified that some ps_facetedsearch module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.
This vulnerability impacts
In the security patch, we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.
Users can also simply remove the unwanted vendor/phpunit folder.
https://nvd.nist.gov/vuln/detail/CVE-2017-9841
If you have any questions or comments about this advisory, email us at [email protected]