You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Unsafe deserialization in Yii 2
High severity
GitHub Reviewed
Published
Sep 14, 2020
in
yiisoft/yii2
•
Updated Feb 7, 2024
Impact
Remote code execution in case application calls
unserialize()
on user input containing specially crafted string.Patches
2.0.38
Workarounds
Add the following to BatchQueryResult.php:
For more information
If you have any questions or comments about this advisory, contact us through security form.
References