Impact
Deserialization of untrusted data from the mimes parameter could lead to remote code execution.
Patches
Fixed in 3.0.9
Workarounds
Not needed, a composer update will solve it in a non-breaking way.
References
Reported responsibly Vladislav Gladkiy at Positive Technologies.
Impact
Deserialization of untrusted data from the
mimesparameter could lead to remote code execution.Patches
Fixed in 3.0.9
Workarounds
Not needed, a
composer updatewill solve it in a non-breaking way.References
Reported responsibly Vladislav Gladkiy at Positive Technologies.