VDB
Sign up
HIGH8.1

GHSA-qvqm-h22r-4cp9

Laravel Framework RCE Vulnerability

Quick fix

GHSA-qvqm-h22r-4cp9 — laravel/framework: upgrade to the fixed version with the command below.

composer require laravel/framework:^5.6.30

Details

In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in `Illuminate/Encryption/Encrypter.php` and PendingBroadcast in `gadgetchains/Laravel/RCE/3/chain.php` in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/laravel/framework
Introduced in: 0

No fixed version published yet for laravel/framework (composer). Pin to a known-safe version or switch to an alternative.

Packagist/laravel/framework
Introduced in: 5.6.0Fixed in: 5.6.30
Fixcomposer require laravel/framework:^5.6.30

References