PKSA-sjsn-7352-ttw3 Security Advisory
-
[MEDIUM] CVE-2020-5220: Ability to define unintended serialisation groups via HTTP header which might lead to data exposure
PKSA-sjsn-7352-ttw3 CVE-2020-5220 GHSA-8vp7-j5cj-vvm2
Affected package: sylius/resource-bundle
Affected version: >=1.0.0,<1.1.0|>=1.1.0,<1.2.0|>=1.2.0,<1.3.0|>=1.3.0,<1.3.13|>=1.4.0,<1.4.6|>=1.5.0,<1.5.1|>=1.6.0,<1.6.3
Reported by:
GitHub, FriendsOfPHP/security-advisories