Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfg4-p438-p874

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Laravel Framework Deserialization Vulnerability

The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the PendingCommand class in PendingCommand.php.

Пакеты

Наименование

laravel/framework

composer
Затронутые версииВерсия исправления

>= 5.7.0, < 6.20.44

6.20.44

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

ubuntu
почти 7 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

nvd
почти 7 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

9.8 Critical

CVSS3

Дефекты

CWE-502