CVE-2024-45290·PHP vulnerability
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the XLSX file, PhpSpreadsheet retrieves the image size and type by reading the file contents, if the provided path is a URL. By using specially crafted `php://filter` URLs an attacker can leak the contents of any file or URL. Note that this vulnerability is different from GHSA-w9xv-qf98-ccq4, and resides in a different component. An attacker can access any file on the server, or leak information form arbitrary URLs, potentially exposing sensitive information such as AWS IAM credentials. This issue has been addressed in release versions 1.29.2, 2.1.1, and 2.3.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.
- Severity
- high
- Software
- PHP
- Fixed in
- 2.3.0
- Published
- 2024-10-07
Affected versions
From: 2.2.0
Until: 2.3.0
Fixed in: 2.3.0
How to fix this CVE
Update PHP and PHPSpreadsheet library to version 2.3.0 or later to patch the arbitrary file disclosure vulnerability in XLSX media handling. This vulnerability allows attackers to craft malicious spreadsheet files that leak sensitive server files when processed. Immediate patching is critical if your application processes user-supplied XLSX files or integrates with PHPSpreadsheet for spreadsheet operations.
sudo dnf update php php-common php-curl php-xml -yDefensia detects this vulnerability
WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block HTTP requests containing 'php://' protocol handlers in file upload parameters or XLSX file content metadata. Implement strict MIME type validation for spreadsheet uploads and reject files with embedded external URL references unless explicitly required.How to check if you are affected
- Run 'php -v' to check the installed PHP version and verify if PHPSpreadsheet is included in your application dependencies.
- Check your project's composer.lock or vendor directory for PHPSpreadsheet: grep -r 'PhpSpreadsheet' composer.lock or ls -la vendor/phpoffice/
- Review application logs for requests uploading or processing XLSX files with embedded external media URLs, particularly looking for php://filter:// protocol references.
- Verify the patch was applied by running 'composer show phpoffice/phpspreadsheet' and confirming version is 2.3.0 or higher, or 'php -m' to confirm PHP core patches are installed.
FAQ
What is CVE-2024-45290?
This vulnerability in PHPSpreadsheet allows attackers to embed php://filter URLs as media references in XLSX files, enabling arbitrary file disclosure or credential theft when the spreadsheet is processed. The library attempts to fetch remote image metadata, which can be exploited to leak sensitive files like configuration or AWS credentials.
Is CVE-2024-45290 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been disclosed, but the attack requires minimal complexity and should be patched immediately.
What versions of PHP/PHPSpreadsheet are affected by CVE-2024-45290?
PHPSpreadsheet versions 2.2.0 through 2.3.0 (exclusive) are vulnerable. Earlier versions 1.x and 2.1.1 have patches available, and version 2.3.0 and later are safe.
How do I check if my server is vulnerable to CVE-2024-45290?
Run 'composer show phpoffice/phpspreadsheet' to check the installed version; if it's between 2.2.0 and 2.2.x, your system is vulnerable. If the library is not installed via Composer, check your vendor folder for the PhpSpreadsheet directory and review its version constant.
Does Defensia detect CVE-2024-45290?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PHP or PHPSpreadsheet is installed on a monitored server, CVE-2024-45290 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-45290. Free for 1 server.
Get started free