
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability affects datadog/dd-trace PHP library versions 0.30.0 to 0.30.2, where the ddtrace.request_init_hook circumvents the open_basedir INI directive. This security issue was discovered and disclosed in September 2019, impacting the core functionality of the PHP tracer extension (GitHub Advisory).
The vulnerability stems from the request init hook not being properly bound by the open_basedir INI directive, which is a PHP security feature that limits file operations to specific directories. The issue was identified in the core extension functionality where PG(open_basedir) was being set to NULL, effectively bypassing the security restrictions (DataDog Commit).
The vulnerability allows the request init hook to bypass open_basedir restrictions, potentially enabling access to files and directories that should be restricted by PHP's security settings. This could lead to unauthorized file access outside of the intended directory scope (Security Advisory).
The vulnerability affects versions 0.30.0 and 0.30.1 of the datadog/dd-trace package. While no specific exploit reports were found in the wild, the vulnerability could be exploited in environments relying on open_basedir for security restrictions (GitHub Release).
The issue was fixed in version 0.30.2 of datadog/dd-trace. Users are strongly recommended to upgrade to this version or later. The fix ensures that the request init hook remains properly bound by the open_basedir INI directive and includes additional sandboxing mechanisms to prevent errors or exceptions from affecting the main script execution (GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."