barryvdh / laravel-snappy

Laravel Snappy PDF
MIT License
2.59k stars 289 forks source link

CVE-2023-28115 #504

Closed golf-junkie closed 1 year ago

golf-junkie commented 1 year ago

Is the vulnerability identified in CVE-2023-28115 applicable to the laravel-snappy library? If laravel-snappy is affected, when will you upgrade to the latest versions to mitigate the vulnerability?

barryvdh commented 1 year ago

You should be able to just update composer so you get the latest patched snappy version.

golf-junkie commented 1 year ago

Thanks for checking the vulnerability.