Skip to content

Commit

Permalink
CVE-2018-17057 for wallabag/tcpdf, not fixed yet
Browse files Browse the repository at this point in the history
  • Loading branch information
Jeroen Vermeulen committed Oct 14, 2018
1 parent 94ae2ba commit 62a9bc6
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions wallabag/tcpdf/CVE-2018-17057.yaml
@@ -0,0 +1,8 @@
title: Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
link: https://github.com/tecnickcom/TCPDF/commit/1861e33fe05f653b67d070f7c106463e7a5c26ed
cve: CVE-2018-17057
branches:
master:
time: null
versions: ['<6.2.22']
reference: composer://wallabag/tcpdf

0 comments on commit 62a9bc6

Please sign in to comment.