yiisoft/yii deserializing untrusted user input can lead to remote code execution
Description
Published by the National Vulnerability Database
Nov 14, 2023
Published to the GitHub Advisory Database
Nov 14, 2023
Reviewed
Nov 14, 2023
Last updated
Nov 14, 2023
Impact
Affected versions of
yiisoft/yii
are vulnerable to Remote Code Execution (RCE) if the application callsunserialize()
on arbitrary user input.Patches
Upgrade
yiisoft/yii
to version 1.1.29 or higher.For more information
See the following links for more details:
If you have any questions or comments about this advisory, contact us through security form.
References