HIGH8.5
GHSA-7xr2-8ff7-6fjq
zenstruck/collection passing callable string to EntityRepository::find() and query()
Quick fix
GHSA-7xr2-8ff7-6fjq — zenstruck/collection: upgrade to the fixed version with the command below.
composer require zenstruck/collection:^0.2.1Details
### Impact Passing _callable strings_ (ie `system`) caused the function to be executed.
### Patches Fixed in [v0.2.1](https://github.com/zenstruck/collection/releases/tag/v0.2.1).
### Workarounds Do not allow passing user strings to `EntityRepository::find()` or `query()`.
### References [Fix commit](https://github.com/zenstruck/collection/commit/f4b1c488206e1b1581b06fcd331686846f13f19c).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zenstruck/collection
Introduced in:
0Fixed in: 0.2.1Fix
composer require zenstruck/collection:^0.2.1References
- https://github.com/zenstruck/collection/security/advisories/GHSA-7xr2-8ff7-6fjq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37473[ADVISORY]
- https://github.com/zenstruck/collection/commit/f4b1c488206e1b1581b06fcd331686846f13f19c[WEB]
- https://github.com/zenstruck/collection[PACKAGE]
- https://github.com/zenstruck/collection/releases/tag/v0.2.1[WEB]