GHSA-mw2w-2hj2-fg8q
yiisoft/yii deserializing untrusted user input can lead to remote code execution
Quick fix
GHSA-mw2w-2hj2-fg8q — yiisoft/yii: upgrade to the fixed version with the command below.
composer require yiisoft/yii:^1.1.29Details
### Impact Affected versions of `yiisoft/yii` are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input.
### Patches Upgrade `yiisoft/yii` to version 1.1.29 or higher.
### For more information See the following links for more details: - [Git commit](https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06) - https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection
If you have any questions or comments about this advisory, [contact us through security form](https://www.yiiframework.com/security).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/yiisoft/yii/security/advisories/GHSA-mw2w-2hj2-fg8q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47130[ADVISORY]
- https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06[WEB]
- https://github.com/yiisoft/yii[PACKAGE]
- https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection[WEB]