The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://korelogic.com/Resources/Advisories/KL-001-2024-002.txt | third party advisory |
http://seclists.org/fulldisclosure/2024/Mar/12 |