Advisory 2024-12/02 PHP Vulnerability
December 13, 2024
Vulnerability type | Improper input validation, injection |
Severity factors | This vulnerability has a CVSS severity rating of 7.2 high. |
Versions affected | FileCloud versions 23.241.4 and earlier are affected. |
Version fixed | FileCloud version 23.241.5 and later |
Description
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, and 8.3.* before 8.3.14, when using streams with some additional features, the URI is not correctly sanitized, which enables malicious actors to perform arbitrary requests and gain access to internal resources.
Fix
FileCloud version 23.241.5.28040 upgrades PHP to version 8.2.26 to fix this vulnerability
What you should do to fix this vulnerability
- If you are using FileCloud Server, we recommended that you update to the latest version, which is 23.241.5.28040 or greater.
Note: Hotfixes applied after updating FileCloud to version 23.241.4 must be reapplied after upgrading to version 23.241.5. - If you are using FileCloud Online, your site will be upgraded to the latest version on December 14 through December 15.
If you have any questions about this advisory, please contact FileCloud support.