Sec Bug->Req #68019 [Opn]: FPM INI settings from Env
| From: | bukka@php.net | Date: | Sat, 04 Dec 2021 18:19:10 +0000 |
| Subject: | Sec Bug->Req #68019 [Opn]: FPM INI settings from Env | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238170@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68019&edit=1
ID: 68019
Updated by: bukka@php.net
Reported by: manuel-php at mausz dot at
Summary: FPM INI settings from Env
Status: Open
-Type: Security
+Type: Feature/Change Request
Package: FPM related
PHP Version: Irrelevant
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: Y
New Comment:
This is well known and it's on purpose and there are already requests about this so nothing
secret about it. I will keep it open as feature request until planned mitigations (e.g. configurable
disabling of PHP_ADMIN_VALUE) are implemented.
Previous Comments:
------------------------------------------------------------------------
[2014-09-13 23:37:55] manuel-php at mausz dot at
Description:
------------
Setting up PHP-FPM with Apache has been improved recently. However unless most other HTTP servers
Apache supports modifying the environment variables from .htaccess files. Since PHP-FPM supports
passing INI settings from environment this combination allows the user to modify any INI settings.
A simple example is:
SetEnv PHP_ADMIN_VALUE "enable_dl=1"
Related to this is another security problem mentioned in the script referenced in https://bugs.php.net/bug.php?id=63965. This script
tries to connect to the FPM socket and change the INI settings for new workers.
I don't know of a good solution. Apache admins could disallow directives like SetEnv, SetEnvIf,
BrowserMatch, etc.. however they're quite useful for CGI an FCGI support. So the best solution
I came up with is adding a new configuration setting which enables/disables reading PHP_ADMIN_VALUE
from environment.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68019&edit=1