{"id":"GHSA-wq43-8r5p-w3mc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-wq43-8r5p-w3mc","summary":"contao/core PHP object injection vulnerability allows for arbitrary code execution","details":"PHP object injection vulnerability was identified in contao/core due to untrusted data being passed to `deserialize()` function.\n","published":"2024-05-15T18:31:04Z","modified":"2024-11-29T05:39:58.333024Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/core","fixedVersion":"2.11.14"},{"ecosystem":"Packagist","name":"contao/core","fixedVersion":"3.2.5"}],"fix":{"url":"https://github.com/contao/core/commit/d67c46c1f1283134e3050244cfdda0ef26fa5cd4","label":"contao/core@d67c46c"},"references":[{"type":"WEB","url":"https://github.com/contao/core/issues/6695"},{"type":"WEB","url":"https://github.com/contao/core/commit/d67c46c1f1283134e3050244cfdda0ef26fa5cd4"},{"type":"WEB","url":"https://github.com/contao/core/commit/f939b5be8a0048ef779def3289e2072febef1b37"},{"type":"WEB","url":"https://contao.org/en/news/major-security-hole-found-in-contao.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/2014-02-13.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:39:58.333024Z"}}