9.8 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Boost <= 2.0.3 - Unauthenticated PHP Object Injection via STYXKEY-BOOST_USER_LOCATION Cookie
The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
References
Affected products
- =<2.0.3
Matching in nixpkgs
pkgs.boost
Collection of C++ libraries
pkgs.booster
Fast and secure initramfs generator
pkgs.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.boost177
None
pkgs.boost178
Collection of C++ libraries
pkgs.boost179
Collection of C++ libraries
pkgs.boost180
Collection of C++ libraries
pkgs.boost181
Collection of C++ libraries
pkgs.boost182
Collection of C++ libraries
pkgs.boost183
Collection of C++ libraries
pkgs.boost186
Collection of C++ libraries
pkgs.boost187
Collection of C++ libraries
pkgs.boost188
Collection of C++ libraries
pkgs.boost189
Collection of C++ libraries
pkgs.boost190
Collection of C++ libraries
pkgs.catboost
High-performance library for gradient boosting on decision trees
pkgs.boost-sml
Header only state machine library with no dependencies
pkgs.mev-boost
Ethereum block-building middleware
pkgs.boost-build
None
pkgs.pianobooster
MIDI file player that teaches you how to play the piano
-
nixos-unstable 1.0.0-unstable-2023-01-22
- nixpkgs-unstable 1.0.0-unstable-2023-01-22
- nixos-unstable-small 1.0.0-unstable-2023-01-22
pkgs.nosql-booster
GUI tool for MongoDB Server
pkgs.xgboostWithCuda
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.emacs-lsp-booster
Emacs LSP performance booster
pkgs.python312Packages.boost
None
pkgs.python313Packages.boost
Collection of C++ libraries
pkgs.python314Packages.boost
Collection of C++ libraries
pkgs.python312Packages.xgboost
None
pkgs.python313Packages.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.python314Packages.xgboost
Scalable, Portable and Distributed Gradient Boosting (GBDT, GBRT or GBM) Library
pkgs.python313Packages.catboost
High-performance library for gradient boosting on decision trees
pkgs.python314Packages.catboost
High-performance library for gradient boosting on decision trees
pkgs.ibus-engines.typing-booster
Completion input method for faster typing
-
nixos-unstable 2.30.6-with-hunspell
- nixpkgs-unstable 2.30.6-with-hunspell
- nixos-unstable-small 2.30.6-with-hunspell
pkgs.gnomeExtensions.boost-volume
Boosts volume above limits
pkgs.gnomeExtensions.volume-boost
A toggle to Boosts volume above limits | Fork of https://github.com/shaquibimdad/gnome_ext_volume_boost
pkgs.haskellPackages.xgboost-haskell
XGBoost library for Haskell
pkgs.perlPackages.BoostGeometryUtils
Bindings for the Boost Geometry library
pkgs.perl5Packages.BoostGeometryUtils
Bindings for the Boost Geometry library
pkgs.python312Packages.boost-histogram
None
pkgs.python313Packages.boost-histogram
Python bindings for the C++14 Boost::Histogram library
pkgs.python314Packages.boost-histogram
Python bindings for the C++14 Boost::Histogram library
pkgs.perl538Packages.BoostGeometryUtils
None
pkgs.perl540Packages.BoostGeometryUtils
None
pkgs.ibus-engines.typing-booster-unwrapped
Completion input method for faster typing
pkgs.gnomeExtensions.frequency-boost-switch
Add a toggle to enable/disable CPU frequency boost in Gnome Quick Settings menu.
pkgs.pkgsRocm.tests.testers.hasCmakeConfigModules.boost-has-boost_mpi
Test whether boost-1.89.0 exposes cmake-config modules boost_mpi
pkgs.pkgsRocm.tests.testers.hasCmakeConfigModules.boost_mpi-does-not-have-mpi
Test whether boost-1.89.0 exposes cmake-config modules boost_mpi
Package maintainers
-
@ivan-tkatchev Ivan Tkatchev <tkatchev@gmail.com>
-
@prtzl Matej Blagsic <matej.blagsic@protonmail.com>
-
@PlushBeaver Dmitry Kozlyuk <dmitry.kozliuk+nixpkgs@gmail.com>
-
@natsukium Tomoya Otabi <nixpkgs@natsukium.com>
-
@Icy-Thought Icy-Thought <gilganyx@pm.me>
-
@honnip Jung seungwoo <me@honnip.page>
-
@ekimber Edward Kimber <ekimber@protonmail.com>
-
@guillaumematheron Guillaume Matheron <guillaume_nix@matheron.eu>
-
@UlyssesZh Ulysses Zhan <ulysseszhan@gmail.com>
-
@veprbl Dmitry Kalinkin <veprbl@gmail.com>
-
@nviets Nathan Viets <nathan.g.viets@gmail.com>