High severity7.8NVD Advisory· Published Jun 7, 2016· Updated May 6, 2026
CVE-2015-5723
CVE-2015-5723
Description
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
doctrine/annotationsPackagist | < 1.2.7 | 1.2.7 |
doctrine/cachePackagist | >= 1.4.0, < 1.4.2 | 1.4.2 |
doctrine/commonPackagist | < 2.4.3 | 2.4.3 |
doctrine/commonPackagist | >= 2.5.0-stable, < 2.5.1 | 2.5.1 |
doctrine/ormPackagist | >= 2.5.0, < 2.5.1 | 2.5.1 |
doctrine/mongodb-odmPackagist | < 1.0.2 | 1.0.2 |
doctrine/mongodb-odm-bundlePackagist | < 3.0.1 | 3.0.1 |
zendframework/zendframework1Packagist | >= 1.12.0, < 1.12.16 | 1.12.16 |
zendframework/zend-cachePackagist | >= 2.5.0, < 2.5.3 | 2.5.3 |
aws/aws-sdk-phpPackagist | >= 3.0.0, < 3.2.1 | 3.2.1 |
doctrine/cachePackagist | >= 1.0.0, < 1.3.2 | 1.3.2 |
zendframework/zend-cachePackagist | >= 2.4.0, < 2.4.8 | 2.4.8 |
zendframework/zendframeworkPackagist | >= 2.4.0, < 2.4.8 | 2.4.8 |
zfcampus/zf-apigility-doctrinePackagist | >= 1.0.0, < 1.0.3 | 1.0.3 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-pw5c-xqf2-6xc2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-5723ghsaADVISORY
- framework.zend.com/security/advisory/ZF2015-07nvdWEB
- www.debian.org/security/2015/dsa-3369nvdWEB
- framework.zend.com/security/advisory/ZF2015-07ghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/aws/aws-sdk-php/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/doctrine/cache/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/doctrine/orm/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-cache/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2015-5723.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/zfcampus/zf-apigility-doctrine/CVE-2015-5723.yamlghsaWEB
- github.com/aws/aws-sdk-php/releases/tag/3.2.1ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUOghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUOghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67ghsaWEB
- www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.htmlghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUO/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67/nvd
News mentions
0No linked articles in our index yet.