GHSA-86hp-xrhj-fhpq
Dashboard / Vulnerabilities / GHSA-86hp-xrhj-fhpq
Summary: TYPO3 Vulnerable to Insecure Deserialization
Details: TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-12747, https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-12747.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-12747.yaml, https://github.com/TYPO3-CMS/core, https://typo3.org/cms/release-news/typo3-8-release-notes, https://typo3.org/security/advisory/typo3-core-sa-2019-020, http://github.com/TYPO3/typo3/commit/647aa7afa582983cddc547fa106d31e2b1ef34fe
Affected packages
Package
Name: typo3/cms-core
Purl: pkg:composer/typo3/cms-core
Affected ranges
Type: ECOSYSTEM
Events:
