GHSA-pfg4-p438-p874
Dashboard / Vulnerabilities / GHSA-pfg4-p438-p874
Summary: Laravel Framework Deserialization Vulnerability
Details: The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the `__destruct` method of the PendingCommand class in `PendingCommand.php`.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-9081, https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html, https://github.com/laravel/framework, https://github.com/laravel/framework/discussions/40184, https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce
Affected packages
Package
Name: laravel/framework
Purl: pkg:composer/laravel/framework
Affected ranges
Type: ECOSYSTEM
Events:
