vendor:
php-fpm
by:
Unknown
9.8
CVSS
CRITICAL
Remote Code Execution
20
CWE
Product Name: php-fpm
Affected Version From: PHP 7+
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2019-11043
CPE: a:php:php_fpm
Metasploit:
https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2022-31631/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apachemodphp-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/alma_linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2019-11043/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2019-11043/
Platforms Tested: Linux, Windows, Mac
2019
PHuiP-FPizdaM
This is an exploit for a bug in php-fpm (CVE-2019-11043). In certain nginx + php-fpm configurations, the bug is possible to trigger from the outside. This means that a web user may get code execution if you have vulnerable config.
Mitigation:
Add file existence checks like try_files $uri =404 or if (-f $uri) in the nginx configuration. Upgrade to a version of php-fpm that includes the fix for this vulnerability.