In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade october/october to version 4.3.5 or higher.
Affected versions of this package are vulnerable to Improper Input Validation via the ResizeImageItem::fromObject process. An attacker can cause metadata deserialization and potentially execute arbitrary code by supplying a crafted phar:// path as untrusted input to the |resize filter or the ResizeImages::resize() API. This is only exploitable if a template author or backend configuration passes untrusted input into these image resizing functions without proper validation.
This vulnerability can be mitigated by auditing template code and backend widget configuration for uses of the |resize filter (or direct ResizeImages::resize() calls) that accept untrusted string input, and validating that the scheme is http or https before passing it in.