{"id":"GHSA-mvf6-3f2g-xfxf","summary":"endroid/qr-code-bundle File Disclosure via logo_path query parameter","details":"Versions of endroid/qr-code-bundle prior to 3.4.2 are affected by a security vulnerability that allows disclosure of files through the logo_path query parameter. The vulnerability arises from the improper handling of non-image data as the logo, which could lead to unintended file disclosure.","modified":"2024-11-29T05:37:08.887462Z","published":"2024-05-15T21:05:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-15T21:05:13Z","nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/endroid/qr-code-bundle/commit/51928eaaa30e7db1fd3f1076744dcbc8f8cec8c8"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/endroid/qr-code-bundle/2019-12-22.yaml"},{"type":"PACKAGE","url":"https://github.com/endroid/qr-code-bundle"},{"type":"WEB","url":"https://github.com/endroid/qr-code-bundle/releases/tag/3.4.2"}],"affected":[{"package":{"name":"endroid/qr-code-bundle","ecosystem":"Packagist","purl":"pkg:composer/endroid/qr-code-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.2"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.2.2","3.2.3","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.4.0","3.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-mvf6-3f2g-xfxf/GHSA-mvf6-3f2g-xfxf.json"}}],"schema_version":"1.9.0"}