CVE-2022-41922: yiisoft/yii before v1.1.27 vulnerable to Remote Code Execution if the application calls `unserialize()` on arbitrary user input
yiisoft/yii before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls unserialize() on arbitrary user input. This has been patched in 1.1.27.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
yiisoft/yiito a version that resolves this vulnerability.Fixed in 1.1.27
Event History
Frequently Asked Questions
What is CVE-2022-41922?
`CVE-2022-41922` is a vulnerability in `yiisoft/yii` before version `1.1.27` that allows remote code execution if the application calls `unserialize()` on arbitrary user input.
How severe is CVE-2022-41922?
The severity of `CVE-2022-41922` is critical, with a CVSS score of `9.8`.
How does CVE-2022-41922 affect `yiisoft/yii`?
`CVE-2022-41922` affects `yiisoft/yii` before version `1.1.27`.
How can I fix CVE-2022-41922?
To fix `CVE-2022-41922`, update `yiisoft/yii` to version `1.1.27` or later.
Where can I find more information about CVE-2022-41922?
You can find more information about `CVE-2022-41922` on the GitHub commit page (link: [https://github.com/yiisoft/yii/commit/ed67b7cc57216557c5c595c6650cdd2d3aa41c52]) and the GitHub security advisories page (link: [https://github.com/yiisoft/yii/security/advisories/GHSA-442f-wcwq-fpcf]).