HIGH
GHSA-wq43-8r5p-w3mc
contao/core PHP object injection vulnerability allows for arbitrary code execution
Quick fix
GHSA-wq43-8r5p-w3mc — contao/core: upgrade to the fixed version with the command below.
composer require contao/core:^2.11.14Details
PHP object injection vulnerability was identified in contao/core due to untrusted data being passed to `deserialize()` function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/contao/core/issues/6695[WEB]
- https://github.com/contao/core/commit/d67c46c1f1283134e3050244cfdda0ef26fa5cd4[WEB]
- https://github.com/contao/core/commit/f939b5be8a0048ef779def3289e2072febef1b37[WEB]
- https://contao.org/en/news/major-security-hole-found-in-contao.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/2014-02-13.yaml[WEB]