CVE-2021-29476: Insecure Deserialization of untrusted data in rmccue/requests
Published Nov 3, 2020
·Updated
Insecure Deserialization of untrusted data
Other sources
Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been patched and users of Requests 1.6.0, 1.6.1 and 1.7.0 should update to version 1.8.0.
Affected Software
4 affected components
composer/rmccue/requests>=1.6.0, <1.8.0
WordPress Requests=1.6.0
WordPress Requests=1.6.1
WordPress Requests=1.7.0
Remediation
Patch Available
Event History
Nov 3, 2020
Advisory Published
08:51 AM
Apr 27, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-29476.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Insecure Deserialization of untrusted data'.
3
What is the severity level of CVE-2021-29476?
The severity level of CVE-2021-29476 is critical with a score of 9.8.
4
Which software versions are affected by this vulnerability?
The versions 1.6.0, 1.6.1, and 1.7.0 of 'Requests' in PHP are affected by this vulnerability.
5
How can I fix the vulnerability CVE-2021-29476?
To fix the vulnerability CVE-2021-29476, update 'Requests' library to version 1.8.0.