CIVI-SA-2019-08: Arbitrary File Read

Publié
2019-02-22 09:00
Written by

This vulnerability allowed attackers to access the content of arbitrary files (in a common configuration).

NOTE: The patch-set for this issue overlapped with the patch-set for CIVI-SA-2019-01, but the cause, exploit, and risks are distinct.

Security Risk
Highly Critical
Vulnerability
Access Bypass
Affected Versions

CiviCRM versions 5.10.2 and earlier

 

Fixed Versions

CIviCRM versions 5.10.3 and 5.7.4

 

Solutions

Upgrade to the latest CiviCRM 5.10.3+ or 5.7.4+.

 

Credits

Eileen McNuaghton of Wikimedia and Tim Otten of CiviCRM for identifying the issue.

Eileen McNuaghton of Wikimedia, Seamus Lee of Australian Greens, and Tim Otten of CiviCRM for fixing the issue.