CVE-2021-23592: Deserialization of Untrusted Data
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-23592?
CVE-2021-23592 is a vulnerability in the topthink/framework package before version 6.0.12 that allows for Deserialization of Untrusted Data due to an insecure unserialize method in the Driver class.
How severe is CVE-2021-23592?
CVE-2021-23592 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2021-23592?
To fix CVE-2021-23592, update to version 6.0.12 or later of the topthink/framework package.
What software versions are affected by CVE-2021-23592?
Versions of the topthink/framework package up to and excluding 6.0.12 are affected by CVE-2021-23592.
Where can I find more information about CVE-2021-23592?
You can find more information about CVE-2021-23592 in the following references: - [GitHub commit](https://github.com/top-think/framework/commit/d3b5aeae94bc71bae97977d05cd12c3e0550905c) - [GitHub release](https://github.com/top-think/framework/releases/tag/v6.0.12) - [Snyk vulnerability report](https://snyk.io/vuln/SNYK-PHP-TOPTHINKFRAMEWORK-2385695)