CVE-2019-20453

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-20453
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-20453.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-20453
Published
2020-03-17T14:15:11Z
Modified
2025-01-08T06:02:33.881990Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in the page plugins/uploader.http/HttpDownload.php. An authenticated user with basic privileges can inject objects and achieve remote code execution.

References

Affected packages

Git / github.com/pydio/pydio-core

Affected ranges

Type
GIT
Repo
https://github.com/pydio/pydio-core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

6.*

6.2alpha
6.2beta
6.2rc

ajaxplorer-core-4.*

ajaxplorer-core-4.3.1
ajaxplorer-core-4.3.2
ajaxplorer-core-4.3.3
ajaxplorer-core-4.3.4

ajaxplorer-core-5.*

ajaxplorer-core-5.0.0
ajaxplorer-core-5.0.1
ajaxplorer-core-5.0.2
ajaxplorer-core-5.0.3

pydio-core-5.*

pydio-core-5.1.0
pydio-core-5.1.1
pydio-core-5.2.0
pydio-core-5.2.1
pydio-core-5.2.2
pydio-core-5.2.3
pydio-core-5.2.4
pydio-core-5.2.5
pydio-core-5.3.1
pydio-core-5.3.2
pydio-core-5.3.3
pydio-core-5.3.4

pydio-core-6.*

pydio-core-6.0.0
pydio-core-6.0.1
pydio-core-6.0.2
pydio-core-6.0.3
pydio-core-6.0.4
pydio-core-6.0.5
pydio-core-6.0.6
pydio-core-6.0.7
pydio-core-6.0.8
pydio-core-6.2.0
pydio-core-6.2.1
pydio-core-6.2.2
pydio-core-6.2.2rc
pydio-core-6.2.2rc2
pydio-core-6.2.2rc3
pydio-core-6.3.1
pydio-core-6.4.0
pydio-core-6.4.0rc1
pydio-core-6.4.0rc2
pydio-core-6.4.0rc3
pydio-core-6.4.1
pydio-core-6.4.2
pydio-core-6.4.2rc1
pydio-core-6.5.1
pydio-core-6.5.2
pydio-core-6.5.3
pydio-core-6.5.4
pydio-core-6.5.5

pydio-core-7.*

pydio-core-7.0.0
pydio-core-7.0.1
pydio-core-7.0.2
pydio-core-7.0.3
pydio-core-7.0.4

pydio-core-8.*

pydio-core-8.0.0
pydio-core-8.0.1
pydio-core-8.0.2
pydio-core-8.2.0
pydio-core-8.2.1
pydio-core-8.2.2
pydio-core-8.2.3