Intel

AIKIDO-2024-10087

spatie/image-optimizer is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2024-34515 Published May 6, 2024

50

Medium Risk

This Affects:

phpspatie/image-optimizer
0.0.3 - 1.7.2
Fixed in 1.7.3
Are you affected? Scan for Free

TL;DR

Affected versions of the spatie/image-optimizer package deserialize untrusted data without sufficiently verifying that the resulting data is valid. The package fails to apply adequate checks when copying an image file, which could lead to potential security risks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spatie/image-optimizer is vulnerable to Deserialization of Untrusted Data in versions 0.0.3 - 1.7.2.

How to fix this

Upgrade the spatie/image-optimizer library to the patch version.