OSV 1.4.0 · github-reviewed · 修改于 2020-01-08 11:06
发布时间
2020-01-08 11:10
GitHub 审查时间
2020-01-08 11:06
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/01/GHSA-wqq8-mqj9-697f/GHSA-wqq8-mqj9-697f.json
We have identified that some autoupgrade module ZIP archives have been built with phpunit dev dependencies. PHPUnit contains a php script that would allow, on a webserver, an attacker to perform a RCE.
This vulnerability impacts
You can read PrestaShop official statement about this vulnerability here.
In the security patch, we look for the unwanted vendor/phpunit folder and remove it if we find it. This allows users to fix the security issue when upgrading.
Users can also simply remove the unwanted vendor/phpunit folder.
https://nvd.nist.gov/vuln/detail/CVE-2017-9841
If you have any questions or comments about this advisory, email us at [email protected]