Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-5723


Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.


Published

2016-06-07T14:06:08.697

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zend zend-cache ≤ 2.4.7 Yes
Application zend zend-cache 2.5.0 Yes
Application zend zend-cache 2.5.1 Yes
Application zend zend-cache 2.5.2 Yes
Operating System debian debian_linux 7.0 Yes
Operating System debian debian_linux 8.0 Yes
Application doctrine-project object_relational_mapper ≤ 2.4.7 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project object_relational_mapper 2.5.0 Yes
Application doctrine-project doctrinemongodbbundle 3.0.0 Yes
Application zend zend_framework ≤ 2.4.7 Yes
Application doctrine-project common ≤ 2.4.2 Yes
Application doctrine-project common 2.5.0 Yes
Application doctrine-project common 2.5.0 Yes
Application doctrine-project annotations ≤ 1.2.6 Yes
Application doctrine-project mongodb-odm ≤ 1.0.1 Yes
Application zend zend_framework ≤ 1.12.15 Yes
Application doctrine-project cache ≤ 1.3.1 Yes
Application doctrine-project cache 1.4.0 Yes
Application doctrine-project cache 1.4.1 Yes
Application zend zf-apigility-doctrine ≤ 1.0.2 Yes

References