{"id":"GHSA-pfg4-p438-p874","summary":"Laravel Framework Deserialization Vulnerability","details":"The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the `__destruct` method of the PendingCommand class in `PendingCommand.php`.","aliases":["CVE-2019-9081"],"modified":"2024-02-16T08:24:40.221686Z","published":"2022-05-14T01:31:22Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-07-19T20:35:32Z","nvd_published_at":"2019-02-24T17:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-9081"},{"type":"WEB","url":"https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html"},{"type":"PACKAGE","url":"https://github.com/laravel/framework"},{"type":"WEB","url":"https://github.com/laravel/framework/discussions/40184"},{"type":"WEB","url":"https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce"}],"affected":[{"package":{"name":"laravel/framework","ecosystem":"Packagist","purl":"pkg:composer/laravel/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"6.20.44"}]}],"versions":["v5.7.0","v5.7.1","v5.7.10","v5.7.11","v5.7.12","v5.7.13","v5.7.14","v5.7.15","v5.7.16","v5.7.17","v5.7.18","v5.7.19","v5.7.2","v5.7.20","v5.7.21","v5.7.22","v5.7.23","v5.7.24","v5.7.25","v5.7.26","v5.7.27","v5.7.28","v5.7.29","v5.7.3","v5.7.4","v5.7.5","v5.7.6","v5.7.7","v5.7.8","v5.7.9","v5.8.0","v5.8.1","v5.8.10","v5.8.11","v5.8.12","v5.8.13","v5.8.14","v5.8.15","v5.8.16","v5.8.17","v5.8.18","v5.8.19","v5.8.2","v5.8.20","v5.8.21","v5.8.22","v5.8.23","v5.8.24","v5.8.25","v5.8.26","v5.8.27","v5.8.28","v5.8.29","v5.8.3","v5.8.30","v5.8.31","v5.8.32","v5.8.33","v5.8.34","v5.8.35","v5.8.36","v5.8.37","v5.8.38","v5.8.4","v5.8.5","v5.8.6","v5.8.7","v5.8.8","v5.8.9","v6.0.0","v6.0.1","v6.0.2","v6.0.3","v6.0.4","v6.1.0","v6.10.0","v6.10.1","v6.11.0","v6.12.0","v6.13.0","v6.13.1","v6.14.0","v6.15.0","v6.15.1","v6.16.0","v6.17.0","v6.17.1","v6.18.0","v6.18.1","v6.18.10","v6.18.11","v6.18.12","v6.18.13","v6.18.14","v6.18.15","v6.18.16","v6.18.17","v6.18.18","v6.18.19","v6.18.2","v6.18.20","v6.18.21","v6.18.22","v6.18.23","v6.18.24","v6.18.25","v6.18.26","v6.18.27","v6.18.28","v6.18.29","v6.18.3","v6.18.30","v6.18.31","v6.18.32","v6.18.33","v6.18.34","v6.18.35","v6.18.36","v6.18.37","v6.18.38","v6.18.39","v6.18.4","v6.18.40","v6.18.41","v6.18.42","v6.18.43","v6.18.5","v6.18.6","v6.18.7","v6.18.8","v6.18.9","v6.19.0","v6.19.1","v6.2.0","v6.20.0","v6.20.1","v6.20.10","v6.20.11","v6.20.12","v6.20.13","v6.20.14","v6.20.15","v6.20.16","v6.20.17","v6.20.18","v6.20.19","v6.20.2","v6.20.20","v6.20.21","v6.20.22","v6.20.23","v6.20.24","v6.20.25","v6.20.26","v6.20.27","v6.20.28","v6.20.29","v6.20.3","v6.20.30","v6.20.31","v6.20.32","v6.20.33","v6.20.34","v6.20.35","v6.20.36","v6.20.37","v6.20.38","v6.20.39","v6.20.4","v6.20.40","v6.20.41","v6.20.42","v6.20.43","v6.20.5","v6.20.6","v6.20.7","v6.20.8","v6.20.9","v6.3.0","v6.4.0","v6.4.1","v6.5.0","v6.5.1","v6.5.2","v6.6.0","v6.6.1","v6.6.2","v6.7.0","v6.8.0","v6.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-pfg4-p438-p874/GHSA-pfg4-p438-p874.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}