Laravel 9.1.8, when processing attacker-controlled data for deserialization, allows Remote Code Execution (RCE) via an unserialized pop chain in __destruct in Illuminate\Broadcasting\PendingBroadcast.php and __call in Faker\Generator.php.
References
| Link | Resource |
|---|---|
| https://github.com/1nhann/vulns/issues/3 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-06-07 16:15
Updated : 2022-06-14 13:52
NVD link : CVE-2022-31279
Mitre link : CVE-2022-31279
JSON object : View
Products Affected
laravel
- laravel
CWE
CWE-502
Deserialization of Untrusted Data
