Candidate: CVE-2019-9081 PublicDate: 2019-02-24 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9081 Description: The Illuminate component of Laravel Framework 5.7.x has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the PendingCommand class in PendingCommand.php. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_php-laravel-framework: upstream_php-laravel-framework: needs-triage trusty_php-laravel-framework: ignored (out of standard support) xenial_php-laravel-framework: ignored (out of standard support) bionic_php-laravel-framework: DNE focal_php-laravel-framework: DNE hirsute_php-laravel-framework: ignored (reached end-of-life) impish_php-laravel-framework: DNE jammy_php-laravel-framework: DNE devel_php-laravel-framework: DNE