CVE-2019-11830
CRITICALPharStreamWrapper <2.1.1-3.1.1 - Deserialization
Title source: llmDescription
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
References (6)
Scores
CVSS v3
9.8
EPSS
0.0249
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
typo3/pharstreamwrapper
< 2.1.1
typo3/phar-stream-wrapper
< 2.1.1Packagist
Timeline
Published
May 09, 2019
Tracked Since
Feb 18, 2026