{"id":"CVE-2021-37704","aliases":["GHSA-cvh5-p6r6-g2qc"],"url":"https://o3.security/vulnerability/CVE-2021-37704","summary":"Exposed phpinfo() leadked via documentation files","details":"### Impact\nThe `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc).\n\n### Patches\nOnly the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5.\nOlder versions such as v5, v4 are not longer supported and will **NOT** be patched.\n\n### Workarounds\nProtect the `/vendor` directory from public access.\n\n### References\nThe first issue revealing this vulnerability is located here: https://github.com/flextype/flextype/issues/567\nV6 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/815\nV7 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/814\nV8 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/813\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [our issue tracker](https://github.com/PHPSocialNetwork/phpfastcache/issues)\n* Email us at [security@geolim4.com](mailto:security@geolim4.com)\n","published":"2021-08-12T20:15:07.267Z","modified":"2026-08-27T08:14:44.214029Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"phpfastcache/phpfastcache","fixedVersion":"6.1.5"},{"ecosystem":"Packagist","name":"phpfastcache/phpfastcache","fixedVersion":"7.1.2"},{"ecosystem":"Packagist","name":"phpfastcache/phpfastcache","fixedVersion":"8.0.7"}],"fix":{"url":"https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51","label":"PHPSocialNetwork/phpfastcache@41a77d0"},"references":[{"type":"ADVISORY","url":"https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807"},{"type":"ADVISORY","url":"https://github.com/PHPSocialNetwork/phpfastcache/pull/814"},{"type":"ADVISORY","url":"https://github.com/PHPSocialNetwork/phpfastcache/pull/815"},{"type":"ADVISORY","url":"https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc"},{"type":"ADVISORY","url":"https://packagist.org/packages/phpfastcache/phpfastcache"},{"type":"REPORT","url":"https://github.com/flextype/flextype/issues/567"},{"type":"FIX","url":"https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51"},{"type":"FIX","url":"https://github.com/PHPSocialNetwork/phpfastcache/pull/813"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-37704"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:14:44.214029Z"}}