Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.
References
Link | Resource |
---|---|
https://packagist.org/packages/nette/application | Third Party Advisory |
https://packagist.org/packages/nette/nette | Third Party Advisory |
https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94 | Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2020-10-01 12:15
Updated : 2021-11-18 08:47
NVD link : CVE-2020-15227
Mitre link : CVE-2020-15227
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
debian
- debian_linux
nette
- application