Sec Bug->Req #79417 [Asn]: PHP-FPM: php_admin_value can be overwritten in .htaccess

From: Date: Sat, 04 Dec 2021 18:18:05 +0000
Subject: Sec Bug->Req #79417 [Asn]: PHP-FPM: php_admin_value can be overwritten in .htaccess
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-238169@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79417&edit=1 ID: 79417 Updated by: bukka@php.net Reported by: tk at all-inkl dot com Summary: PHP-FPM: php_admin_value can be overwritten in .htaccess Status: Assigned -Type: Security +Type: Feature/Change Request Package: FPM related Operating System: linux ubuntu18, PHP Version: Irrelevant Assigned To: bukka Block user comment: N Private report: Y New Comment: This is well known and it's on purpose and there are already requests about this so nothing secret about it. I will keep it open as feature request until planned mitigations (e.g. configurable disabling of PHP_ADMIN_VALUE) are implemented. Previous Comments: ------------------------------------------------------------------------ [2020-05-06 07:53:36] tk at all-inkl dot com okay, I got it. However, then it should be more clear that the PHP_INI_* modes are only reliable for PHP as an apache mod: https://www.php.net/manual/en/configuration.changes.modes.php ------------------------------------------------------------------------ [2020-04-26 19:52:10] bukka@php.net The linked documentation is for running PHP as an Apache module which has nothing to do with FPM and php_admin_value in FPM config. I guess the reason why you can overwrite it is just that SetEnv in Apache adds FCGI env. The PHP_ADMIN_VALUE and PHP_VALUE is something that allows overwriting PHP ini on the server and it's been always there. It's on purpose and we can't change it as it would likely break some applications. ------------------------------------------------------------------------ [2020-04-14 20:06:18] stas@php.net Would be nice to hear from FPM maintainers as the code as I see it directly uses this variable so I have hard time imagining how it could be unintentional... maybe there's some confusion going on between code, documentation and intentions. ------------------------------------------------------------------------ [2020-04-14 11:01:54] tk at all-inkl dot com no it's not. it should not be able to be overwritten at all. see documentation https://www.php.net/manual/en/configuration.changes.php: php_admin_value name value Sets the value of the specified directive. This _can not_ be used in .htaccess files. Any directive type set with php_admin_value can not be overridden by .htaccess or ini_set(). To clear a previously set value use none as the value. it will also trigger an error when you try to use php_admin_value in same directory: [core:alert] [pid 14623:tid 140080005994240] [client 172.16.16.252:0] /var/www/test1/.htaccess: php_admin_value not allowed here, referer: http://localhost/ but with SetEnv you can bypass this setup ------------------------------------------------------------------------ [2020-04-14 03:54:01] stas@php.net Isn't that what PHP_ADMIN_VALUE is for? If it's not intended, do not set AllowOverride All for these directories. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79417 -- Edit this bug report at https://bugs.php.net/bug.php?id=79417&edit=1

« previous php.bugs (#238169) next »