GHSA-3hxw-g85p-qgxm
CRITICALCVE-2019-11830PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
- Affected
- >= 2.0.0, < 2.1.1, >= 3.0.0, < 3.1.1
- Fixed in
- 2.1.1
- Weakness
- CWE-502
- Published
- 2022-05-24
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereference