Lucene search

K
cve[email protected]CVE-2015-5723
HistoryJun 07, 2016 - 2:06 p.m.

CVE-2015-5723

2016-06-0714:06:08
CWE-264
web.nvd.nist.gov
62
cve
2015
5723
security
vulnerability
doctrine
annotations
cache
common
orm
mongodb odm
mongodb odm bundle
world-writable
permissions
cache directories
local users
arbitrary code execution

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

Affected configurations

NVD
Node
zendzend-cacheRange2.4.7
OR
zendzend-cacheMatch2.5.0
OR
zendzend-cacheMatch2.5.1
OR
zendzend-cacheMatch2.5.2
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
doctrine-projectobject_relational_mapperRange2.4.7
OR
doctrine-projectobject_relational_mapperMatch2.5.0
OR
doctrine-projectobject_relational_mapperMatch2.5.0alpha1
OR
doctrine-projectobject_relational_mapperMatch2.5.0alpha2
OR
doctrine-projectobject_relational_mapperMatch2.5.0beta1
OR
doctrine-projectobject_relational_mapperMatch2.5.0rc1
OR
doctrine-projectobject_relational_mapperMatch2.5.0rc2
Node
doctrine-projectdoctrinemongodbbundleMatch3.0.0
Node
zendzend_frameworkRange2.4.7
Node
doctrine-projectcommonRange2.4.2
OR
doctrine-projectcommonMatch2.5.0
OR
doctrine-projectcommonMatch2.5.0beta1
Node
doctrine-projectannotationsRange1.2.6
Node
doctrine-projectmongodb-odmRange1.0.1
Node
zendzend_frameworkRange1.12.15
Node
doctrine-projectcacheRange1.3.1
OR
doctrine-projectcacheMatch1.4.0
OR
doctrine-projectcacheMatch1.4.1
Node
zendzf-apigility-doctrineRange1.0.2

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%