Lucene search

K
typo3TYPO3 AssociationTYPO3-PSA-2019-008
HistoryMay 08, 2019 - 12:00 a.m.

By-passing protection of Phar Stream Wrapper Interceptor

2019-05-0800:00:00
TYPO3 Association
typo3.org
17

0.023 Low

EPSS

Percentile

89.8%

Insecure deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application. In July 2018, the vulnerability of insecure deserialization when executing Phar archives was addressed by removing the known attack vector in the TYPO3 core. For more details read the corresponding TYPO3 advisory.

0.023 Low

EPSS

Percentile

89.8%