Sec Bug->Req #79417 [Asn]: PHP-FPM: php_admin_value can be overwritten in .htaccess
| From: | bukka@php.net | Date: | Sat, 04 Dec 2021 18:18:05 +0000 |
| Subject: | Sec Bug->Req #79417 [Asn]: PHP-FPM: php_admin_value can be overwritten in .htaccess | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238169@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79417&edit=1
ID: 79417
Updated by: bukka@php.net
Reported by: tk at all-inkl dot com
Summary: PHP-FPM: php_admin_value can be overwritten in
.htaccess
Status: Assigned
-Type: Security
+Type: Feature/Change Request
Package: FPM related
Operating System: linux ubuntu18,
PHP Version: Irrelevant
Assigned To: bukka
Block user comment: N
Private report: Y
New Comment:
This is well known and it's on purpose and there are already requests about this so nothing
secret about it. I will keep it open as feature request until planned mitigations (e.g. configurable
disabling of PHP_ADMIN_VALUE) are implemented.
Previous Comments:
------------------------------------------------------------------------
[2020-05-06 07:53:36] tk at all-inkl dot com
okay, I got it. However, then it should be more clear that the PHP_INI_* modes are only reliable for
PHP as an apache mod:
https://www.php.net/manual/en/configuration.changes.modes.php
------------------------------------------------------------------------
[2020-04-26 19:52:10] bukka@php.net
The linked documentation is for running PHP as an Apache module which has nothing to do with FPM and
php_admin_value in FPM config.
I guess the reason why you can overwrite it is just that SetEnv in Apache adds FCGI env. The
PHP_ADMIN_VALUE and PHP_VALUE is something that allows overwriting PHP ini on the server and
it's been always there. It's on purpose and we can't change it as it would likely
break some applications.
------------------------------------------------------------------------
[2020-04-14 20:06:18] stas@php.net
Would be nice to hear from FPM maintainers as the code as I see it directly uses this variable so I
have hard time imagining how it could be unintentional... maybe there's some confusion going on
between code, documentation and intentions.
------------------------------------------------------------------------
[2020-04-14 11:01:54] tk at all-inkl dot com
no it's not. it should not be able to be overwritten at all.
see documentation https://www.php.net/manual/en/configuration.changes.php:
php_admin_value name value
Sets the value of the specified directive. This _can not_ be used in .htaccess files. Any directive
type set with php_admin_value can not be overridden by .htaccess or ini_set(). To clear a previously
set value use none as the value.
it will also trigger an error when you try to use php_admin_value in same directory:
[core:alert] [pid 14623:tid 140080005994240] [client 172.16.16.252:0] /var/www/test1/.htaccess:
php_admin_value not allowed here, referer: http://localhost/
but with SetEnv you can bypass this setup
------------------------------------------------------------------------
[2020-04-14 03:54:01] stas@php.net
Isn't that what PHP_ADMIN_VALUE is for? If it's not intended, do not set AllowOverride All
for these directories.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=79417
--
Edit this bug report at https://bugs.php.net/bug.php?id=79417&edit=1