GHSA-484f-743f-6jx2
Object injection in cookie driver in phpfastcache
Quick fix
GHSA-484f-743f-6jx2 — phpfastcache/phpfastcache: upgrade to the fixed version with the command below.
composer require phpfastcache/phpfastcache:^5.0.13Details
### Impact An possible object injection has been discovered in cookie driver prior 5.0.13 versions (of 5.x releases).
### Patches The issue has been addressed by enforcing JSON conversion when deserializing
### Workarounds If you can't fix it, use another driver such as "Files" (Filesystem)
### References Fixing release: https://github.com/PHPSocialNetwork/phpfastcache/releases/tag/5.0.13
### For more information If you have any questions or comments about this advisory: * Open an issue in [the issue tracker](https://github.com/PHPSocialNetwork/phpfastcache/issues) * Email us at [security@geolim4.com](mailto:security@geolim4.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0Fixed in: 5.0.13composer require phpfastcache/phpfastcache:^5.0.13References
- https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-484f-743f-6jx2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2019-16774[ADVISORY]
- https://github.com/PHPSocialNetwork/phpfastcache/commit/c4527205cb7a402b595790c74310791f5b04a1a4[WEB]
- https://github.com/PHPSocialNetwork/phpfastcache[PACKAGE]
- https://github.com/PHPSocialNetwork/phpfastcache/releases/tag/5.0.13[WEB]
- https://github.com/advisories/GHSA-484f-743f-6jx2[ADVISORY]