Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

composer提示有安全漏洞 #3066

Closed
YvesHo0968 opened this issue Sep 12, 2024 · 2 comments
Closed

composer提示有安全漏洞 #3066

YvesHo0968 opened this issue Sep 12, 2024 · 2 comments

Comments

@YvesHo0968
Copy link

所属功能组件

其它

ThinkPHP 版本

8.0.3

操作系统

mac

错误信息

composer audit

Found 2 security vulnerability advisories affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package           | topthink/framework                                                               |
| Severity          | critical                                                                         |
| CVE               | CVE-2024-44902                                                                   |
| Title             | ThinkPHP deserialization vulnerability                                           |
| URL               | https://github.com/advisories/GHSA-f4wh-359g-4pq7                                |
| Affected versions | >=6.1.3,<=8.0.4                                                                  |
| Reported at       | 2024-09-09T21:31:23+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+
+-------------------+----------------------------------------------------------------------------------+
| Package           | topthink/framework                                                               |
| Severity          | medium                                                                           |
| CVE               | CVE-2024-34467                                                                   |
| Title             | ThinkPHP Cross-Site Scripting Vulnerability                                      |
| URL               | https://github.com/advisories/GHSA-969f-v7jv-pgj3                                |
| Affected versions | <6.0.17|>=6.1.0,<6.1.5|>=8.0.0,<8.0.4                                            |
| Reported at       | 2024-05-04T21:30:33+00:00                                                        |
+-------------------+----------------------------------------------------------------------------------+

其它说明

No response

@YvesHo0968 YvesHo0968 added the bug label Sep 12, 2024
@liu21st
Copy link
Member

liu21st commented Sep 12, 2024

第二个最新版是没问题的 第一个漏洞但凡有点安全意识的基本都不用担心 没有一个项目会傻到这种程度去反序列化用户输入的东西

@big-dream big-dream removed the bug label Sep 12, 2024
@big-dream
Copy link
Contributor

Duplicate of #3059

@big-dream big-dream marked this as a duplicate of #3059 Sep 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants