Skip to content

Pagekit Docker Image Exposes composer.lock File #7

@mbiesiad

Description

@mbiesiad

Hi, first of all - great work with the repo.

Pagekit Docker Image Exposes composer.lock File

Description

The community Pagekit Docker image (pagekit/pagekit on Docker Hub) allows public access to the composer.lock file located in the web root.

Proof of Concept

Screenshot

poc-dockerImage-pageKit-composerLock

Details

CWE:

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-284: Improper Access Control
  • CWE-285: Improper Authorization
  • CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory

References

Best regards,

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions