Vulnerability DatabaseGHSA-6xch-2vxx-5pvr

GHSA-6xch-2vxx-5pvr
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-6xch-2vxx-5pvr) affects eZ Platform's handling of executable access rules on Platform.sh (eZ Cloud). Discovered in 2019, this security issue impacts eZ Platform versions >= 2.5.0, < 2.5.4, >= 1.13.0, < 1.13.5.1, and >= 1.7.0, < 1.7.9.1. The vulnerability was assigned a moderate severity rating (GitHub Advisory).

Technical details

The vulnerability stems from the recommended Apache/Nginx virtual host configuration for eZ Platform, which includes a rewrite rule for blocking access to executable files in the var directory. This rule fails to function properly when using eZ Platform Cloud on the Platform.sh cloud service. The issue specifically affects the platform's ability to properly enforce access restrictions on executable files (GitHub Advisory).

Impact

The primary impact of this vulnerability is that executable files in the var directory may become downloadable when deployed on Platform.sh. While these files cannot be executed unless specifically configured (which is strongly discouraged), the unauthorized download access represents a deviation from the platform's intended security model (GitHub Advisory).

Exploitability

The vulnerability affects all Platform.sh setups of eZ Platform. While the files cannot be executed without explicit configuration, they remain accessible for download, presenting a limited but notable security concern (GitHub Advisory).

Mitigation and workarounds

The issue has been resolved through security updates distributed via Composer as ezsystems/ezplatform versions 1.7.9.1, 1.13.5.1, and 2.5.4. The fix adds a specific rule to the .platform.app.yaml configuration file that replicates the effect of the existing rewrite rule, preventing access to executable files with an 'Access Denied' response (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management