Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1996 | zenstruck/collections is a set of helpers for iterating/paginating/filtering collections. Passing _callable strings_ (ie `system`) caused the function to be executed. This would result in a limited subset of specific user input being executed as if it were code. This issue has been addressed in commit `f4b1c48820` and included in release version 0.2.1. Users are advised to upgrade. Users unable to upgrade should ensure that user input is not passed to either `EntityRepository::find()` or `query()`. |
Github GHSA |
GHSA-7xr2-8ff7-6fjq | zenstruck/collection passing callable string to EntityRepository::find() and query() |
Fri, 18 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:zenstruck:collection:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-18T17:42:36.436Z
Reserved: 2023-07-06T13:01:36.998Z
Link: CVE-2023-37473
Updated: 2024-08-02T17:16:30.334Z
Status : Modified
Published: 2023-07-14T21:15:09.047
Modified: 2024-11-21T08:11:47.053
Link: CVE-2023-37473
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA