VDB
Sign up
HIGH8.1

GHSA-442f-wcwq-fpcf

Prevent RCE when deserializing untrusted user input

Quick fix

GHSA-442f-wcwq-fpcf — yiisoft/yii: upgrade to the fixed version with the command below.

composer require yiisoft/yii:^1.1.27

Details

### Impact Affected versions of `yiisoft/yii` are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input.

### Patches Upgrade `yiisoft/yii` to version 1.1.27 or higher.

### For more information See the following links for more details: - [Git commit](https://github.com/yiisoft/yii/commit/ed67b7cc57216557c5c595c6650cdd2d3aa41c52) - https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection

If you have any questions or comments about this advisory, [contact us through security form](https://www.yiiframework.com/security).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii
Introduced in: 0Fixed in: 1.1.27
Fixcomposer require yiisoft/yii:^1.1.27

References