CVE-2022-2870 MEDIUM

CVE-2022-2870: laravel deserialization

Vendor Unspecified
Product laravel
Weakness CWE-502 · Unsafe deserialization
Published August 17, 2022
Last update April 15, 2025

CVSS base score

4.1/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

Description

A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206501 was assigned to this vulnerability.

Key dates

Disclosure timeline

August 17, 2022 CVE published
April 15, 2025 Record updated