Code Injection in Smarty - CVE-2024-35226
Published: May 29, 2024
Vulnerability identifier: #VU89862
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35226
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary PHP code on the target system.
The vulnerability exists due to improper input validation when handling "extends-tag" attribute. Template authors can inject and execute arbitrary PHP code by choosing a malicious file name for an extends-tag.
Affected software
Smarty
Debian Linux
Ubuntu
Storage Sentinel Anomaly Scan Engine
smarty3 (Ubuntu package)
smarty4 (Ubuntu package)
smarty3 (Debian package)
smarty4 (Debian package)
Debian Linux
Ubuntu
Storage Sentinel Anomaly Scan Engine
smarty3 (Ubuntu package)
smarty4 (Ubuntu package)
smarty3 (Debian package)
smarty4 (Debian package)
How to mitigate CVE-2024-35226
Install updates from vendor's website.
Smarty - addressed in versions 4.5.3, 5.2.0
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
smarty3 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1, 3.1.39-2ubuntu1.22.04.2, 3.1.48-1ubuntu0.24.04.1, 3.1.48-1ubuntu0.24.10.1
smarty4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.3.1-1ubuntu0.24.10.1
smarty3 (Debian package) - update to 3.1.47-2+deb12u1
smarty4 (Debian package) - update to 4.3.0-1+deb12u2
Storage Sentinel Anomaly Scan Engine - update to 1.1.12
smarty3 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.1.34+20190228.1.c9f0de05+selfpack1-1ubuntu0.1, 3.1.39-2ubuntu1.22.04.2, 3.1.48-1ubuntu0.24.04.1, 3.1.48-1ubuntu0.24.10.1
smarty4 (Ubuntu package) - addressed in versions Ubuntu Pro, 4.3.1-1ubuntu0.24.10.1
smarty3 (Debian package) - update to 3.1.47-2+deb12u1
smarty4 (Debian package) - update to 4.3.0-1+deb12u2