Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. laravel/framework
  4. ›
  5. CVE-2019-9081

CVE-2019-9081: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

May 14, 2022 (updated July 19, 2023)

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

References

  • github.com/Laworigin/Laworigin.github.io/blob/master/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/index.html
  • github.com/advisories/GHSA-pfg4-p438-p874
  • github.com/laravel/framework/discussions/40184
  • laworigin.github.io/2019/02/21/laravelv5-7%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96rce/
  • nvd.nist.gov/vuln/detail/CVE-2019-9081

Code Behaviors & Features

Detect and mitigate CVE-2019-9081 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.7.0 before 6.20.44

Fixed versions

  • 6.20.44

Solution

Upgrade to version 6.20.44 or above.

Weakness

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Source file

packagist/laravel/framework/CVE-2019-9081.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:40 +0000.