CRITICAL9.8
GHSA-3fpv-54ff-wqfj
Deserialization of Untrusted Data in topthink/framework
Quick fix
GHSA-3fpv-54ff-wqfj — topthink/framework: upgrade to the fixed version with the command below.
composer require topthink/framework:^6.0.12Details
The package topthink/framework before version 6.0.12 is vulnerable to Deserialization of Untrusted Data due to insecure `unserialize` method in the `Driver` class.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
0Fixed in: 6.0.12Fix
composer require topthink/framework:^6.0.12References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23592[ADVISORY]
- https://github.com/top-think/framework/commit/d3b5aeae94bc71bae97977d05cd12c3e0550905c[WEB]
- https://github.com/top-think/framework[PACKAGE]
- https://github.com/top-think/framework/releases/tag/v6.0.12[WEB]
- https://snyk.io/vuln/SNYK-PHP-TOPTHINKFRAMEWORK-2385695[WEB]