Relative Path Traversal in oneup/uploader-bundle
Published Feb 5, 2020
8.8
HIGHCVSS 3.1
EPSS 3.93%
Description
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or (4) filename parameter to DropzoneController.php; the (5) qqpartindex, (6) qqfilename, or (7) qquuid parameter to FineUploaderController.php; the (8) x-file-id or (9) x-file-name parameter to MooUploadController.php; or the (10) name or (11) chunk parameter to PluploadController.php. This is fixed in versions 1.9.3 and 2.1.5.
Affected products
-
- Version < 1.9.3StatusaffectedConstraints-
- Version >= 2.0.0, < 2.1.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1up-Lab | Oneup/uploader-Bundle | n/a |
|
- < 1.9.3
- ≥ 1.9.4 · < 2.1.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/1up-lab/OneupUploaderBundle/commit/a6011449b716f163fe1ae323053077e59212350c x_refsource_MISCPatchThird Party Advisory
- https://github.com/1up-lab/OneupUploaderBundle/security/advisories/GHSA-x8wj-6m73-gfqp x_refsource_CONFIRMThird Party Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/oneup/uploader-bundle/CVE-2020-5237.yaml
- https://github.com/advisories/GHSA-x8wj-6m73-gfqp Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-5237
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-003.txt x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/1up-lab/OneupUploaderBundle/commit/a6011449b716f163fe1ae323053077e59212350c | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/1up-lab/OneupUploaderBundle/security/advisories/GHSA-x8wj-6m73-gfqp | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/FriendsOfPHP/security-advisories/blob/master/oneup/uploader-bundle/CVE-2020-5237.yaml | ||
| https://github.com/advisories/GHSA-x8wj-6m73-gfqp | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-5237 | ||
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-003.txt | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.