{"id":"CVE-2019-9081","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-9081","summary":"Laravel Framework Deserialization Vulnerability","details":"The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the `__destruct` method of the PendingCommand class in `PendingCommand.php`.","published":"2022-05-14T01:31:22Z","modified":"2024-02-16T08:24:40.221686Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"laravel/framework","fixedVersion":"6.20.44"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9081"},{"type":"WEB","url":"https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html"},{"type":"PACKAGE","url":"https://github.com/laravel/framework"},{"type":"WEB","url":"https://github.com/laravel/framework/discussions/40184"},{"type":"WEB","url":"https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-16T08:24:40.221686Z"}}