Impact
Deserialization of untrusted data from the mimes
parameter could lead to remote code execution.
Patches
Fixed in 3.0.9
Workarounds
Not needed, a composer update
will solve it in a non-breaking way.
References
Reported responsibly Vladislav Gladkiy at Positive Technologies.
Impact
Deserialization of untrusted data from the
mimes
parameter could lead to remote code execution.Patches
Fixed in 3.0.9
Workarounds
Not needed, a
composer update
will solve it in a non-breaking way.References
Reported responsibly Vladislav Gladkiy at Positive Technologies.