Sec Bug->Bug #77190 [Asn]: PHP_VALUE can be changed by PHP-FPM environment variables without checking
| From: | cmb@php.net | Date: | Mon, 12 Jul 2021 16:08:08 +0000 |
| Subject: | Sec Bug->Bug #77190 [Asn]: PHP_VALUE can be changed by PHP-FPM environment variables without checking | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-234985@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77190&edit=1
ID: 77190
Updated by: cmb@php.net
Reported by: ricterzheng at gmail dot com
Summary: PHP_VALUE can be changed by PHP-FPM environment
variables without checking
Status: Assigned
-Type: Security
+Type: Bug
Package: FPM related
Operating System: Linux
PHP Version: 7.0Git-2018-11-23 (snap)
Assigned To: bukka
Block user comment: N
Private report: Y
New Comment:
> I think you should read this as open_basedir is not really a
> security measure:
Right, see also <https://externals.io/message/105606>
and <https://externals.io/message/115406>.
> So I don't think this have to be managed as a security bug.
ACK.
Previous Comments:
------------------------------------------------------------------------
[2020-07-16 12:56:55] remi@php.net
Having FPM listening on a public address seems a configuration issue, with a lot of security-related
issues.
The reason one by default, FPM only allow local client (network port) or restricted user list (NDS).
So I don't think this have to be managed as a security bug.
------------------------------------------------------------------------
[2020-07-14 12:44:25] cmb@php.net
Since this is a PHP-FPM issue, it does certainly not affect Windows.
------------------------------------------------------------------------
[2020-03-27 09:22:19] cmb@php.net
Related To: Bug #79417
------------------------------------------------------------------------
[2019-08-14 05:53:38] stas@php.net
Related To: Bug #78305
------------------------------------------------------------------------
[2019-01-25 18:46:48] bukka@php.net
I think you should read this as open_basedir is not really a security measure:
http://www.php.net/security-note.php
I don't think we consider any issues with that as a security issue as there are many ways to
bypass it.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77190
--
Edit this bug report at https://bugs.php.net/bug.php?id=77190&edit=1