2pisoftware / cmfive-core

The core code base for Cmfive, pair this with the cmfive-boilerplate repository for a full featured Cmfive application.
https://cmfive.com
GNU General Public License v3.0
5 stars 6 forks source link

Update aws/aws-sdk-php #369

Open chris-bateman opened 1 month ago

chris-bateman commented 1 month ago

| Package | aws/aws-sdk-php | | Severity | medium | | CVE | CVE-2023-51651 | | Title | Potential URI resolution path traversal in the AWS SDK for PHP | | URL | https://nvd.nist.gov/vuln/detail/CVE-2023-51651 | | Affected versions | >=3.0.0,<3.288.1 | | Reported at | 2023-11-22T00:00:00+00:00 |

DerekCrannaford commented 1 month ago

See:

https://github.com/2pisoftware/cmfive-core/pull/372
https://github.com/2pisoftware/cmfive-boilerplate/pull/182
DerekCrannaford commented 1 month ago

Notes.

Existing mitigation:

Live hotfix possible: