Source |
The Hacker News |
Identifiant |
4383850 |
Date de publication |
2022-04-01 22:49:06 (vue: 2022-04-02 06:05:46) |
Titre |
15-Year-Old Bug in PEAR PHP Repository Could\'ve Enabled Supply Chain Attacks |
Texte |
A 15-year-old security vulnerability has been disclosed in the PEAR PHP repository that could permit an attacker to carry out a supply chain attack, including obtaining unauthorized access to publish rogue packages and execute arbitrary code.
"An attacker exploiting the first one could take over any developer account and publish malicious releases, while the second bug would allow the attacker |
Notes |
|
Envoyé |
Oui |
Condensat |
access account allow any arbitrary attack attacker attacks been bug carry chain code could developer disclosed enabled execute exploiting first has including malicious obtaining old one out over packages pear permit php publish releases repository rogue second security supply take unauthorized vulnerability would year |
Tags |
Vulnerability
|
Stories |
|
Move |
|