Bug 2283822 (CVE-2024-35226) - CVE-2024-35226 php-smarty: php code injection
Summary: CVE-2024-35226 php-smarty: php code injection
Keywords:
Status: NEW
Alias: CVE-2024-35226
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2283823 2283824
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-05-29 15:05 UTC by ybuenos
Modified: 2024-05-29 15:06 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2024-05-29 15:05:37 UTC
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

https://github.com/smarty-php/smarty/commit/0be92bc8a6fb83e6e0d883946f7e7c09ba4e857a
https://github.com/smarty-php/smarty/security/advisories/GHSA-4rmg-292m-wg3w

Comment 1 ybuenos 2024-05-29 15:06:24 UTC
Created php-Smarty tracking bugs for this issue:

Affects: epel-all [bug 2283823]
Affects: fedora-all [bug 2283824]


Note You need to log in before you can comment on or make changes to this bug.