CVE-2021-37704: Exposure of Resource to Wrong Sphere
(updated )
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). the phpinfo()
can be exposed if the /vendor
is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc).
References
Detect and mitigate CVE-2021-37704 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →