Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52qp-jpq7-6c54

Опубликовано: 29 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Insecure Deserialization of untrusted data in rmccue/requests

Impact

Unserialization of untrusted data.

Patches

The issue has been patched and users of Requests 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

References

Publications about the vulnerability:

Originally fixed in WordPress 5.5.2:

Related Security Advisories:

Notification to the Requests repo including a fix in:

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

rmccue/requests

composer
Затронутые версииВерсия исправления

>= 1.6.0, < 1.8.0

1.8.0

EPSS

Процентиль: 84%
0.02219
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 5 лет назад

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

CVSS3: 9.8
nvd
почти 5 лет назад

Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of `Requests` 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.

CVSS3: 9.8
debian
почти 5 лет назад

Requests is a HTTP library written in PHP. Requests mishandles deseria ...

EPSS

Процентиль: 84%
0.02219
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502