MathiasReker / blmvuln

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101
MIT License
41 stars 6 forks source link

BLM Vulnerability #1

Closed cypr00 closed 2 years ago

cypr00 commented 2 years ago

Hi,

I have' just used your BLM Module. All has gone well but there is one file it says maybe infected but when running clean it does not fix it.

The file is ............. The following files looks infected. They will be restored or removed by running the cleaning process: docker-compose.yml

Is this something i can fix or need to be worried about ?

Many thanks in advance.

cypr00

MathiasReker commented 2 years ago

Hello @cypr00

Thank you.

Can you try the new version and tell if you can still reproduce the bug?

Latest version: https://github.com/MathiasReker/blmvuln/releases/latest

cypr00 commented 2 years ago

Hi Mathias,

Many thanks ! That has worked.

One other problem i have found, i receive the below list of file/folder permissions that are insecure and need changing. i run the cleaner and it shows as fixed. I have closed the app and when re opening the app the same files are back again.

The following file/folder permissions is insecure. They will be fixed by running the cleaning process:

HartLarsson commented 2 years ago

I've the same problem and folder are all 0755 permission that is allowed:

` /**

MathiasReker commented 2 years ago

Hello

This issue is fixed in v. 2.1.2 :-)

cypr00 commented 2 years ago

Thanks and great work