FixVibe

critical

Type Confusion in YOURLS Leads to Unauthorized Resource Access

YOURLS (Your Own URL Shortener) versions prior to 1.7.4 contain a critical vulnerability where the application improperly handles resource access using incompatible types. This 'Type Confusion' flaw can be exploited by attackers to bypass intended access controls and interact with restricted system resources.

CVE-2019-14537GHSA-vf23-f26f-mjj9CWE-843

Impact

An attacker can exploit this vulnerability to gain unauthorized access to resources within the YOURLS application [S2]. Due to the nature of type confusion in PHP-based applications, this often leads to authentication bypass or the ability to execute actions that should be restricted to administrative users [S3]. The vulnerability is rated with a CVSS score of 9.8, reflecting its critical impact on system integrity and confidentiality [S1].

Root Cause

The root cause is an 'Access of Resource Using Incompatible Type' (Type Confusion) flaw [S2]. In YOURLS versions earlier than 1.7.4, the application logic fails to strictly validate the data types of inputs used when retrieving or verifying access to specific resources [S3]. When PHP performs loose comparisons or handles unexpected types, it can lead to logic errors that grant access to protected objects or functions [S1].

Technical Details

The vulnerability is identified as CVE-2019-14537 and specifically affects the yourls/yourls product [S2]. It is categorized under CWE-843, which describes situations where a program allocates or uses a resource using one type, but subsequently accesses that resource using a different, incompatible type [S3].

Remediation

Users should update YOURLS to version 1.7.4 or later to resolve this issue [S2]. The fix involves stricter type checking and validation of inputs before they are used in resource-access logic [S3].

Covered by FixVibe

FixVibe's GitHub repo scans flag Composer package evidence and YOURLS source-version constants for yourls/yourls versions lower than 1.7.4, with the patched version to upgrade to.

Type Confusion in YOURLS Leads to Unauthorized Resource Access