VDB
Sign up
CRITICAL9.8

GHSA-w9ph-q4h9-rwq6

CodeIgniter and Kohana vulnerable to PHP Object Injection

Quick fix

GHSA-w9ph-q4h9-rwq6 — codeigniter/framework: upgrade to the fixed version with the command below.

composer require codeigniter/framework:^3.0.0

Details

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter/framework
Introduced in: 0Fixed in: 3.0.0
Fixcomposer require codeigniter/framework:^3.0.0
Packagist/kohana/core
Introduced in: 0Fixed in: 3.3.3
Fixcomposer require kohana/core:^3.3.3

References