{"id":"GHSA-8237-957h-h2c2","summary":"FileManager Deserialization of Untrusted Data vulnerability","details":"### Impact\nDeserialization of untrusted data from the `mimes` parameter could lead to remote code execution.\n\n### Patches\nFixed in 3.0.9\n\n### Workarounds\nNot needed, a `composer update` will solve it in a non-breaking way.\n\n### References\nReported responsibly [Vladislav Gladkiy](https://github.com/catferq) at [Positive Technologies](https://www.ptsecurity.com/ww-en/).","aliases":["CVE-2024-52306"],"modified":"2024-11-18T20:41:59.593102Z","published":"2024-11-13T18:43:02Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-11-13T18:43:02Z","nvd_published_at":"2024-11-13T16:15:20Z","cwe_ids":["CWE-502"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/Laravel-Backpack/FileManager/security/advisories/GHSA-8237-957h-h2c2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52306"},{"type":"WEB","url":"https://github.com/Laravel-Backpack/FileManager/commit/2830498b85e05fb3c92179053b4d7c4a0fdb880b"},{"type":"PACKAGE","url":"https://github.com/Laravel-Backpack/FileManager"}],"affected":[{"package":{"name":"backpack/filemanager","ecosystem":"Packagist","purl":"pkg:composer/backpack/filemanager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.9"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-8237-957h-h2c2/GHSA-8237-957h-h2c2.json"}},{"package":{"name":"backpack/filemanager","ecosystem":"Packagist","purl":"pkg:composer/backpack/filemanager"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.2"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","2.0.0","2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-8237-957h-h2c2/GHSA-8237-957h-h2c2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}