CVE-2017-10993
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
Contao Core directory traversal vulnerability
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://contao.org/en/news/contao-3_5_28.html
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | contao/contao | >=4.0.0,<4.4.1 | 4.4.1 |
| Packagist | contao/core-bundle | >=4.0.0,<4.4.1 | 4.4.1 |
| Packagist | contao/core | >=3.0.0,<3.5.28 | 3.5.28 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| contao | contao_cms | {"endIncluding":"3.5.27"} | |
| contao | contao_cms | 4.0.0 | |
| contao | contao_cms | 4.0.1 | |
| contao | contao_cms | 4.0.2 | |
| contao | contao_cms | 4.0.3 | |
| contao | contao_cms | 4.0.4 | |
| contao | contao_cms | 4.1.0 | |
| contao | contao_cms | 4.1.1 | |
| contao | contao_cms | 4.1.2 | |
| contao | contao_cms | 4.1.3 | |
| contao | contao_cms | 4.2.0 | |
| contao | contao_cms | 4.2.1 | |
| contao | contao_cms | 4.2.2 | |
| contao | contao_cms | 4.2.3 | |
| contao | contao_cms | 4.2.4 | |
| contao | contao_cms | 4.2.5 | |
| contao | contao_cms | 4.3.0 | |
| contao | contao_cms | 4.3.1 | |
| contao | contao_cms | 4.3.2 | |
| contao | contao_cms | 4.3.3 | |
| contao | contao_cms | 4.3.5 | |
| contao | contao_cms | 4.3.6 | |
| contao | contao_cms | 4.3.7 | |
| contao | contao_cms | 4.3.8 | |
| contao | contao_cms | 4.3.9 | |
| contao | contao_cms | 4.3.10 | |
| contao | contao_cms | 4.3.11 | |
| contao | contao_cms | 4.4.0 | |
References
- https://contao.org/en/news/contao-3_5_28.html
- https://nvd.nist.gov/vuln/detail/CVE-2017-10993
- https://contao.org/en/news/contao-4_4_1.html
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2017-10993.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2017-10993.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2017-10993.yaml
CWEs
CWE-22
Verify integrity in audit chain (admin only). AS-IS.