Lucene search

K
typo3TYPO3 AssociationTYPO3-PSA-2019-007
HistoryMay 08, 2019 - 12:00 a.m.

By-passing protection of Phar Stream Wrapper Interceptor

2019-05-0800:00:00
TYPO3 Association
typo3.org
33

0.033 Low

EPSS

Percentile

91.4%

Insecure deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application. In July 2018, the vulnerability of insecure deserialization when executing Phar archives was addressed by removing the known attack vector in the TYPO3 core. For more details read the corresponding TYPO3 advisory.