VDB
Sign up
HIGH

GHSA-2867-6rrm-38gr

Laravel Cookie serialization vulnerability

Quick fix

GHSA-2867-6rrm-38gr — illuminate/cookie: upgrade to the fixed version with the command below.

composer require illuminate/cookie:^5.6.30

Details

Laravel 5.6.30 is a security release of Laravel and is recommended as an immediate upgrade for all users. Laravel 5.6.30 also contains a breaking change to cookie encryption and serialization logic. Refer to [laravel advisory](https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30) for more details and read the notes carefully when upgrading your application.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/illuminate/cookie
Introduced in: 5.5.0Fixed in: 5.6.30
Fixcomposer require illuminate/cookie:^5.6.30

References