CVE-2021-43836

Source
https://cve.org/CVERecord?id=CVE-2021-43836
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43836.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43836
Aliases
Published
2021-12-15T20:15:08Z
Modified
2026-08-07T17:03:07Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The problem is patched with the Versions 1.6.44, 2.2.18, 2.3.8, 2.4.0. For users unable to upgrade overwrite the service sulu_route.generator.expression_token_provider and wrap the translator before passing it to the expression language.

References

Affected packages

Git / github.com/sulu/sulu

Affected ranges

Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:sulu:sulu:2.4.0:rc1:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.6.44"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.2.18"
        },
        {
            "introduced": "2.3.0"
        },
        {
            "fixed": "2.3.8"
        },
        {
            "introduced": "2.4.0-rc1"
        },
        {
            "last_affected": "2.4.0-rc1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.2.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.8
0.7.0
0.7.1
0.8.0
0.8.3
0.8.4
0.8.5
1.*
1.0.0
1.0.0-RC1
1.0.0-RC2
1.0.0-RC3
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
1.1.10
1.1.11
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.3.0
1.3.0-RC1
1.3.0-RC2
1.3.0-RC3
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.6.18
1.6.19
1.6.2
1.6.20
1.6.21
1.6.22
1.6.23
1.6.24
1.6.25
1.6.26
1.6.27
1.6.28
1.6.29
1.6.3
1.6.30
1.6.31
1.6.32
1.6.33
1.6.34
1.6.35
1.6.36
1.6.37
1.6.38
1.6.39
1.6.4
1.6.40
1.6.41
1.6.42
1.6.43
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
2.*
2.0.0
2.1.0-RC1
2.2.0
2.2.0-RC1
2.2.1
2.2.10
2.2.11
2.2.12
2.2.13
2.2.14
2.2.15
2.2.16
2.2.17
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.4.0-RC1
2.4.0-rc1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43836.json"