Impact
An attacker can exploit this vulnerability to gain unauthorized access to resources within the YOURLS application [S2]. Due to the nature of type confusion in PHP-based applications, this often leads to authentication bypass or the ability to execute actions that should be restricted to administrative users [S3]. The vulnerability is rated with a CVSS score of 9.8, reflecting its critical impact on system integrity and confidentiality [S1].
Root Cause
The root cause is an 'Access of Resource Using Incompatible Type' (Type Confusion) flaw [S2]. In YOURLS versions earlier than 1.7.4, the application logic fails to strictly validate the data types of inputs used when retrieving or verifying access to specific resources [S3]. When PHP performs loose comparisons or handles unexpected types, it can lead to logic errors that grant access to protected objects or functions [S1].
Technical Details
The vulnerability is identified as CVE-2019-14537 and specifically affects the yourls/yourls product [S2]. It is categorized under CWE-843, which describes situations where a program allocates or uses a resource using one type, but subsequently accesses that resource using a different, incompatible type [S3].
Remediation
Users should update YOURLS to version 1.7.4 or later to resolve this issue [S2]. The fix involves stricter type checking and validation of inputs before they are used in resource-access logic [S3].
Covered by FixVibe
FixVibe's GitHub repo scans flag Composer package evidence and YOURLS source-version constants for yourls/yourls versions lower than 1.7.4, with the patched version to upgrade to.
