CVE-2019-11831: Moderately critical - Third-party libraries - SA-CORE-2019-007
(updated )
The PharStreamWrapper
(aka phar-stream-wrapper
) package does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar
URL.
References
Detect and mitigate CVE-2019-11831 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →