Unserialized Pop Chain in Laravel
Critical severity
GitHub Reviewed
Published
Jun 8, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Withdrawn
This advisory was withdrawn on Aug 22, 2022
Description
Published by the National Vulnerability Database
Jun 7, 2022
Published to the GitHub Advisory Database
Jun 8, 2022
Reviewed
Jun 8, 2022
Withdrawn
Aug 22, 2022
Last updated
Jan 27, 2023
Withdrawn
This advisory has been withdrawn because it is not a security issue and the CVE has been revoked.
Original Description
Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.
References