GHSA-vv7q-mfpc-qgm5
Dashboard / Vulnerabilities / GHSA-vv7q-mfpc-qgm5
Summary: Unserialized Pop Chain in Laravel
Details: ## Withdrawn This advisory has been withdrawn because it is not a security issue and the CVE has been revoked. ## Original Description Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-31279, https://github.com/1nhann/vulns/issues/1#issuecomment-1213126338, https://github.com/1nhann/vulns/issues/3, https://github.com/ambionics/phpggc/issues/118, https://github.com/laravel/laravel, https://inhann.top/2022/05/17/bypass_wakeup
Affected packages
Package
Name: laravel/laravel
Purl: pkg:composer/laravel/laravel
Affected ranges
Type: ECOSYSTEM
Events:
