Kuthathwe ukulawulwa kwemitapo yolwazi eyi-14 ye-PHP endaweni yokugcina ye-Packagist

Abaphathi bephasela le-Packagist badalule ulwazi mayelana nokuhlasela okuholele ekulawuleni ama-akhawunti emitapo yolwazi ye-PHP engu-14, okuhlanganisa namaphakheji adumile njenge-instantiator (ukufakwa kwezigidi ezingu-526 sekukonke, ukufakwa kwezigidi ezingu-8 ngenyanga, amaphakheji ancike ku-323), sql. -formatter (ukufakwa sekukonke kwezigidi ezingama-94, izinkulungwane ezingama-800 ngenyanga, amaphakheji ancike ku-109), i-doctrine-cache-bundle (ukufakwa okuphelele kwezigidi ezingama-73, izinkulungwane ezingama-500 ngenyanga, amaphakheji ancike ku-348) kanye ne-rcode-detector-decoder (ukufakwa sekukonke kwezigidi ezingama-20 , Izinkulungwane ezingama-400 ngenyanga, amaphakheji ancike ku-66).

Ngemva kokufaka ama-akhawunti engozini, umhlaseli ulungise ifayela le-composer.json, wengeza ulwazi kunkambu yencazelo yephrojekthi ukuthi ubefuna umsebenzi ohlobene nokuvikeleka kolwazi. Ukuze wenze izinguquko kufayela le-composer.json, umhlaseli ubeke esikhundleni sama-URL amakhosombe okuqala ngezixhumanisi eziya kumafoloko ashintshiwe (I-Packagist inikeza kuphela imethadatha enezixhumanisi zamaphrojekthi athuthukiswe ku-GitHub; lapho ifaka “ngokufaka komqambi” noma “isibuyekezo somqambi” umyalo, amaphakheji alandwa ngokuqondile ku-GitHub ). Isibonelo, kuphakheji ye-acmephp, indawo yokugcina exhunyiwe ishintshiwe kusuka ku-acmephp/acmephp kuya ku-neskafe3v1/acmephp.

Ngokusobala, ukuhlaselwa akwenziwanga ukwenza izenzo ezinonya, kodwa njengokubonakaliswa kokungavunyelwa kwesimo sengqondo sokunganaki mayelana nokusetshenziswa kwemininingwane eyimpinda kumasayithi ahlukene. Ngesikhathi esifanayo, umhlaseli, ngokuphambene nomkhuba osumisiwe “wobugebengu bokugebenga,” akazange azise abathuthukisi belabhulali nabaphathi bezindawo zokugcina kusengaphambili mayelana nokuhlolwa okwenziwayo. Kamuva umhlaseli wamemezela ukuthi ngemva kokuba ephumelele ukuthola umsebenzi, uzokhipha umbiko onemininingwane mayelana nezindlela ezasetshenziswa ekuhlaseleni.

Ngokusho kwedatha eshicilelwe abaphathi be-Packagist, wonke ama-akhawunti aphethe amaphakheji onakalisiwe asebenzise amaphasiwedi alula ukuqagela ngaphandle kokunika amandla ukuqinisekiswa kwezinto ezimbili. Kusolwa ukuthi ama-akhawunti agqekeziwe asebenzise amagama ayimfihlo angasetshenziswanga kuphela ku-Packagist, kodwa nakwamanye amasevisi, i-database ye-password eyake yafakwa engozini futhi yatholakala esidlangalaleni. Ukuthwebula ama-imeyili abanikazi bama-akhawunti ayexhunywe ezizindeni eziphelelwe yisikhathi nakho kungase kusetshenziswe njengenketho yokufinyelela.

Amaphakheji onakalisiwe:

  • i-acmephp/acmephp (ukufakwa kwe-124,860 kuyo yonke impilo yephakheji)
  • i-acmephp/core (419,258)
  • acmephp/ssl (531,692)
  • imfundiso/imfundiso-cache-bundle (73,490,057)
  • imfundiso/imfundiso-module (5,516,721)
  • imfundiso/imfundiso-mongo-odm-module (516,441)
  • imfundiso/imfundiso-yesimiso-module (5,103,306)
  • imfundiso/umsunguli (526,809,061)
  • incwadi yokukhula/incwadi yokukhula (97,568
  • jdorn/file-system-cache (32,660)
  • I-jdorn/sql-formatter (94,593,846)
  • ikhanamiryan/qrcode-detector-decoder (20,421,500)
  • object-calisthenics/phpcs-calisthenics-rules (2,196,380)
  • tga/simhash-php, tgalopin/simhashphp (30,555)

Source: opennet.ru

Thenga ukusingathwa okuthembekile kwamasayithi anokuvikelwa kwe-DDoS, amaseva e-VPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekile ngokuvikelwa kwe-DDoS, amaseva e-VPS VDS | ProHoster