CVE-2021-37704

PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
References
Link Resource
https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 Release Notes Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/813 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/814 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/815 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc Third Party Advisory
https://github.com/flextype/flextype/issues/567 Exploit Issue Tracking Third Party Advisory
https://packagist.org/packages/phpfastcache/phpfastcache Product Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 Release Notes Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/813 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/814 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/815 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc Third Party Advisory
https://github.com/flextype/flextype/issues/567 Exploit Issue Tracking Third Party Advisory
https://packagist.org/packages/phpfastcache/phpfastcache Product Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-08-12 20:15

Updated : 2024-11-21 06:15


NVD link : CVE-2021-37704

Mitre link : CVE-2021-37704

CVE.ORG link : CVE-2021-37704


JSON object : View

Products Affected

phpfastcache

  • phpfastcache
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-668

Exposure of Resource to Wrong Sphere