Skip to content

fix: deny PHP execution inside vendor folders under wp-content - #37

Open
YvesCesar wants to merge 2 commits into
mainfrom
fix/deny-php-in-vendor
Open

YvesCesar wants to merge 2 commits into
mainfrom
fix/deny-php-in-vendor

Conversation

@YvesCesar

Copy link
Copy Markdown
Member

The nginx config runs any .php file under the web root. Plugins and themes that install their test suites with Composer get a complete WordPress, the WordPress test suite and WooCommerce under vendor/ inside their own folder, which lives under wp-content/. After a composer install there, a URL like /wp-content/themes/<theme>/vendor/wordpress/wp-admin/setup-config.php opens a fresh WordPress installer that anyone who can reach the port can point at their own database.

This denies running PHP from any vendor/ or vendor-bin/ folder under wp-content/, next to the existing rule for uploads/. Static files there are still served.

Follow-up of LibreSign/saas#21.

Tests

tests/security/vendor-php.bats runs the real default.conf against PHP-FPM:

  • 403 without reaching PHP for a theme vendor/, a plugin vendor/, a plugin vendor-bin/, VENDOR in upper case and %76endor.
  • 200 for a stylesheet under vendor/ and for plugin PHP outside vendor/.

The five blocking cases fail without the new rule.

Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant