{"id":"GHSA-2867-6rrm-38gr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2867-6rrm-38gr","summary":"Laravel Cookie serialization vulnerability","details":"Laravel 5.6.30 is a security release of Laravel and is recommended as an immediate upgrade for all users. Laravel 5.6.30 also contains a breaking change to cookie encryption and serialization logic. Refer to [laravel advisory](https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30) for more details and read the notes carefully when upgrading your application.","published":"2024-05-15T21:56:10Z","modified":"2024-11-29T05:42:35.295201Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"illuminate/cookie","fixedVersion":"5.6.30"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/illuminate/cookie/2018-08-08-1.yaml"},{"type":"PACKAGE","url":"https://github.com/illuminate/cookie"},{"type":"WEB","url":"https://laravel.com/docs/5.6/upgrade#upgrade-5.6.30"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:42:35.295201Z"}}