Prevent RCE when deserializing untrusted user input
Description
Published to the GitHub Advisory Database
Nov 21, 2022
Reviewed
Nov 21, 2022
Published by the National Vulnerability Database
Nov 23, 2022
Last updated
Feb 3, 2023
Impact
Affected versions of
yiisoft/yii
are vulnerable to Remote Code Execution (RCE) if the application callsunserialize()
on arbitrary user input.Patches
Upgrade
yiisoft/yii
to version 1.1.27 or higher.For more information
See the following links for more details:
If you have any questions or comments about this advisory, contact us through security form.
References