An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1tdzJ3LTJoajItZmc4cc4AA3Kz
yiisoft/yii deserializing untrusted user input can lead to remote code execution
Affected versions of
yiisoft/yii are vulnerable to Remote Code Execution (RCE) if the application calls
unserialize() on arbitrary user input.
yiisoft/yii to version 1.1.29 or higher.
For more information
See the following links for more details:
If you have any questions or comments about this advisory, contact us through security form.Permalink: https://github.com/advisories/GHSA-mw2w-2hj2-fg8q
Source: GitHub Advisory Database
Published: 14 days ago
Updated: 14 days ago
CVSS Score: 8.1
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-mw2w-2hj2-fg8q, CVE-2023-47130
Fixed in: 1.1.29