CVE-2021-36567: Critical severity thinkphp vulnerability
Published Dec 6, 2021
·Updated
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\AbstractCache.
Affected Software
1 affected component
ThinkPHP ThinkPHP=6.0.8
Event History
Dec 6, 2021
CVE Published
via MITRE·08:22 PM
Data Sourced
via MITRE·08:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-36567.
2
What is the severity of CVE-2021-36567?
CVE-2021-36567 is classified as critical with a severity score of 9.8.
3
Which software version is affected by CVE-2021-36567?
ThinkPHP v6.0.8 is affected by CVE-2021-36567.
4
What is the component that contains the deserialization vulnerability in ThinkPHP?
The deserialization vulnerability in ThinkPHP is present in the component League\Flysystem\Cached\Storage\AbstractCache.
5
Is there a known fix for CVE-2021-36567?
There is currently no known fix available for CVE-2021-36567. It is recommended to follow the advisory provided by the vendor for updates and patches.