Published in Business

[20190502] - Core - By-passing protection of Phar Stream Wrapper Interceptor

by on08 May 2019
Project: Joomla! SubProject: CMS Impact: Low Severity: Low Versions: 3.9.3 through 3.9.5 Exploit
  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Versions: 3.9.3 through 3.9.5
  • Exploit type: Object Injection
  • Reported Date: 2019-March-27
  • Fixed Date: 2019-May-07

Description

In Joomla 3.9.3, the vulnerability of insecure deserialization when executing Phar archives was addressed by removing the known attack vector in the Joomla core. In order to intercept file invocations like file_exists or stat on compromised Phar archives the base name has to be determined and checked before allowing to be handled by PHP Phar stream handling. The used implementation however is vulnerable to path traversal leading to scenarios where the Phar archive to be assessed is not the actual (compromised) file.

Affected Installs

Joomla! CMS versions 3.9.3 through 3.9.5

Solution

Upgrade to version 3.9.6

Contact

The JSST at the Joomla! Security Centre.

Reported By: Daniel le Gall
Don't miss a thing!
Stay up-to-dated with JoomlaQuickStart
Receive updates for our Joomla news