PHP-FPM Vulnerability (CVE-2019-11043) with NGINX

Published on 31 Aug 2020
Vulnerability

The CVE-2019-11043 vulnerability affects the system that is using an NGINX web server, which is enabled with the Hypertext Preprocessor FastCGI Process Manager (PHP-FPM).

The PHP-FPM is not a core component of PHP. The web hosting provider typically includes it in their PHP environments. This vulnerability can be used in certain conditions to achieve remote code execution.

One way to trigger the vulnerability is to embed a line break (%0a) or carriage return (%0d) character into the request URL, which is then not correctly handled by the regular expression.

Impact

This is a remote code execution vulnerability. So, if the attacker can successfully exploit this vulnerability then he can access the server or can run commands to the server.

Mitigation Or Precaution

The only certain way to address this vulnerability is to upgrade your PHP to the patched release (or later). Else the PHP-FPM can use the NGINX unit to run the PHP applications.

Prathap
Written by
Co-founder, Director

Prathap has around 20 years of experience and has worked on various projects in leading companies like Hitachi, Toshiba, Schneider Electric, ABB, Panasonic, and MicroFuzzy. His expertise lies in architecting, designing, and developing secure projects covering various aspects of software development, processes, and methodology.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo