Remote Code Execution in Laravel
Critical severity
GitHub Reviewed
Published
Apr 9, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Withdrawn
This advisory was withdrawn on Aug 22, 2022
Description
Published by the National Vulnerability Database
Apr 8, 2022
Published to the GitHub Advisory Database
Apr 9, 2022
Reviewed
Apr 12, 2022
Withdrawn
Aug 22, 2022
Last updated
Jan 27, 2023
Withdrawn
This advisory has been withdrawn because it is not a security issue and the CVE has been revoked.
Original Description
A Remote Code Execution (RCE) vulnerability exists in h laravel 5.8.38 via an unserialize pop chain in (1) __destruct in \Routing\PendingResourceRegistration.php, (2) __cal in Queue\Capsule\Manager.php, and (3) __invoke in mockery\library\Mockery\ClosureWrapper.php.
References