{"id":"GHSA-mw2w-2hj2-fg8q","summary":"yiisoft/yii deserializing untrusted user input can lead to remote code execution","details":"### Impact\nAffected versions of `yiisoft/yii` are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input.\n\n### Patches\nUpgrade `yiisoft/yii` to version 1.1.29 or higher.\n\n### For more information\nSee the following links for more details:\n- [Git commit](https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06)\n- https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection\n\nIf you have any questions or comments about this advisory, [contact us through security form](https://www.yiiframework.com/security).","aliases":["CVE-2023-47130"],"modified":"2024-02-16T08:19:54.325789Z","published":"2023-11-14T22:19:28Z","database_specific":{"nvd_published_at":"2023-11-14T21:15:11Z","cwe_ids":["CWE-502"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-11-14T22:19:28Z"},"references":[{"type":"WEB","url":"https://github.com/yiisoft/yii/security/advisories/GHSA-mw2w-2hj2-fg8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47130"},{"type":"WEB","url":"https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06"},{"type":"PACKAGE","url":"https://github.com/yiisoft/yii"},{"type":"WEB","url":"https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection"}],"affected":[{"package":{"name":"yiisoft/yii","ecosystem":"Packagist","purl":"pkg:composer/yiisoft/yii"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.29"}]}],"versions":["1.1.14","1.1.14-rc","1.1.15","1.1.16","1.1.17","1.1.18","1.1.19","1.1.20","1.1.21","1.1.22","1.1.23","1.1.24","1.1.25","1.1.26","1.1.27","1.1.28"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-mw2w-2hj2-fg8q/GHSA-mw2w-2hj2-fg8q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}