PT-2022-20661 · Laravel · Laravel

Published

2022-06-07

·

Updated

2023-03-31

·

CVE-2022-31279

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Laravel version 9.1.8
Description The issue allows Remote Code Execution (RCE) via an unserialized pop chain in destruct in IlluminateBroadcastingPendingBroadcast.php and call in FakerGenerator.php when processing attacker-controlled data for deserialization. This affects industries such as Financial and Retail.
Recommendations For Laravel version 9.1.8, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-31279
GHSA-VV7Q-MFPC-QGM5

Affected Products

Laravel