Skip to content

[GHSA-mpgp-p4pg-fp7c] The alexpechkarev/google-maps Laravel package through 12... - #10182

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10182from
ranjiGT-GHSA-mpgp-p4pg-fp7c
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10182from
ranjiGT-GHSA-mpgp-p4pg-fp7c

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 5, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • References
  • Source code location
  • Summary

Comments
This improvement adds missing Composer package metadata and corrects the affected version range based on the upstream repository history.

The affected package is alexpechkarev/google-maps.

Upstream Git history shows that ssl_verify_peer => FALSE was introduced in commit 7f9dcce, which is tagged as version 1.0.2. Version 1.0.1 does not contain this setting, while version 1.0.2 does. Therefore, the affected range begins at 1.0.2, rather than 1.0.3.

The configuration value is security-relevant: WebService.php loads googlemaps.ssl_verify_peer into $this->verifySSL, which is subsequently passed to CURLOPT_SSL_VERIFYPEER. When false, CURLOPT_SSL_VERIFYHOST is also set to 0.

The insecure default remains present in the latest release, v12.16, and on the current default branch. No patched release has been identified, so the affected range is represented as >= 1.0.2.

This improvement also normalizes the existing CVSS v4 vector by retaining its base metrics while removing unsupported optional X metrics rejected by the GitHub advisory form.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 15:13
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10182 October 5, 2026 15:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Version 1.0.2 is incorrectly marked affected, the narrative contains related historical inaccuracies, and valid CVSS v3 metadata is removed.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates the advisory with package metadata, affected versions, expanded technical details, and references.

Changes:

  • Adds Packagist package and version-range metadata.
  • Expands vulnerability details and source references.
  • Normalizes CVSS v4 metadata and removes CVSS v3.
File Description
advisories/​unreviewed/​2026/​10/​GHSA-mpgp-p4pg-fp7c/​GHSA-mpgp-p4pg-fp7c.json Updates advisory metadata, severity, affected range, description, and references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

],
"details": "The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.",
"summary": "alexpechkarev/google-maps disables TLS certificate verification by default",
"details": "The `alexpechkarev/google-maps` Laravel package disables TLS certificate and hostname verification by default starting in version 1.0.2.\n\nThe bundled configuration sets `ssl_verify_peer` to `FALSE`. This value is loaded by `WebService` and passed directly to `CURLOPT_SSL_VERIFYPEER`. When disabled, the package also sets `CURLOPT_SSL_VERIFYHOST` to `0`.\n\nAs a result, HTTPS connections made by the package do not authenticate the remote TLS endpoint by default. An on-path attacker may therefore be able to intercept or modify Google Maps web-service requests and responses, including potentially exposing API keys transmitted in request URLs.\n\nThe insecure default was introduced in commit `7f9dcce` and is present in release 1.0.2. Version 1.0.1 does not contain the `ssl_verify_peer` configuration option. The insecure default remains present in the latest release, 12.16, and on the current default branch. No patched release has been identified.",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed after checking the upstream Git history and affected release tags.

Although ssl_verify_peer => FALSE was added to the bundled configuration in version 1.0.2, that version does not contain the WebService runtime logic that consumes this setting.

The relevant cURL behavior was introduced by commit d1867b2. The first release containing that commit is 1.0.3.

Direct tag verification shows:

  • 1.0.1: no relevant WebService SSL verification code
  • 1.0.2: no relevant WebService SSL verification code
  • 1.0.3: reads googlemaps.ssl_verify_peer into $verifySSL and passes it to CURLOPT_SSL_VERIFYPEER

Therefore, I agree that the affected range should begin at 1.0.3, not 1.0.2.

Versions through v12.16 remain affected because the bundled configuration continues to set ssl_verify_peer => FALSE. No patched release has been identified.

Comment on lines 12 to +14
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed against the pre-PR advisory metadata from the current upstream main branch.

The existing advisory contains the following CVSS v3.1 vector:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

The improvement was intended only to normalize the CVSS v4 vector by removing the unsupported optional X metrics. It should not remove the existing CVSS v3.1 severity metadata.

Therefore, the advisory should retain both:

  • CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • CVSS v4: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

I agree that the existing CVSS v3.1 entry should be restored.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants