Sec Bug->Bug #77190 [Asn]: PHP_VALUE can be changed by PHP-FPM environment variables without checking

From: Date: Mon, 12 Jul 2021 16:08:08 +0000
Subject: Sec Bug->Bug #77190 [Asn]: PHP_VALUE can be changed by PHP-FPM environment variables without checking
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234985@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77190&edit=1 ID: 77190 Updated by: cmb@php.net Reported by: ricterzheng at gmail dot com Summary: PHP_VALUE can be changed by PHP-FPM environment variables without checking Status: Assigned -Type: Security +Type: Bug Package: FPM related Operating System: Linux PHP Version: 7.0Git-2018-11-23 (snap) Assigned To: bukka Block user comment: N Private report: Y New Comment: > I think you should read this as open_basedir is not really a > security measure: Right, see also <https://externals.io/message/105606> and <https://externals.io/message/115406>. > So I don't think this have to be managed as a security bug. ACK. Previous Comments: ------------------------------------------------------------------------ [2020-07-16 12:56:55] remi@php.net Having FPM listening on a public address seems a configuration issue, with a lot of security-related issues. The reason one by default, FPM only allow local client (network port) or restricted user list (NDS). So I don't think this have to be managed as a security bug. ------------------------------------------------------------------------ [2020-07-14 12:44:25] cmb@php.net Since this is a PHP-FPM issue, it does certainly not affect Windows. ------------------------------------------------------------------------ [2020-03-27 09:22:19] cmb@php.net Related To: Bug #79417 ------------------------------------------------------------------------ [2019-08-14 05:53:38] stas@php.net Related To: Bug #78305 ------------------------------------------------------------------------ [2019-01-25 18:46:48] bukka@php.net I think you should read this as open_basedir is not really a security measure: http://www.php.net/security-note.php I don't think we consider any issues with that as a security issue as there are many ways to bypass it. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77190 -- Edit this bug report at https://bugs.php.net/bug.php?id=77190&edit=1

« previous php.bugs (#234985) next »