GHSA-86r3-4gq8-xw8q
Dashboard / Vulnerabilities / GHSA-86r3-4gq8-xw8q
Summary: Remote Code Execution in Laravel
Details: ## Withdrawn This advisory has been withdrawn because it is not a security issue and the CVE has been revoked. ## Original Description A Remote Code Execution (RCE) vulnerability exists in h laravel 5.8.38 via an unserialize pop chain in (1) __destruct in \Routing\PendingResourceRegistration.php, (2) __cal in Queue\Capsule\Manager.php, and (3) __invoke in mockery\library\Mockery\ClosureWrapper.php.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-43503, https://github.com/1nhann/vulns/issues/1#issuecomment-1213126338, https://github.com/guoyanan1g/Laravel-vul/issues/2#issue-1045655892
Affected packages
Package
Name: laravel/laravel
Purl: pkg:composer/laravel/laravel
Affected ranges
Type: ECOSYSTEM
Events:
