CVE-2019-9081

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

20 Aug 2022, 00:15

Type Values Removed Values Added
CWE CWE-502
References
  • {'url': 'https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html', 'name': 'https://github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html', 'tags': ['Third Party Advisory'], 'refsource': 'MISC'}
  • {'url': 'https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/', 'name': 'https://laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/', 'tags': ['Third Party Advisory', 'Exploit'], 'refsource': 'MISC'}
Summary The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the PendingCommand class in PendingCommand.php. ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CPE cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
CVSS v2 : 7.5
v3 : 9.8
v2 : unknown
v3 : unknown

Information

Published : 2019-02-24 17:29

Updated : 2024-02-04 20:03


NVD link : CVE-2019-9081

Mitre link : CVE-2019-9081

CVE.ORG link : CVE-2019-9081


JSON object : View

Products Affected

No product.

CWE

No CWE.