fuel / core

Fuel PHP Framework - The core of the Fuel v1 framework
http://fuelphp.com
802 stars 335 forks source link

Update composer.json #2201

Closed phpukr closed 7 months ago

phpukr commented 7 months ago

phpseclib < 3.0.34 vulnerable to denial of service

sonarcloud[bot] commented 7 months ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
2.8% 2.8% Duplication

WanWizard commented 7 months ago

Yes, aware of that, we've got a dependabot alert.

Currently looking at the impact, as it is a major version upgrade..

WanWizard commented 7 months ago

First indications are 3.x is not compatible.

A simple login doesn't work anymore, but since Auth doesn't use Crypt, I think it may be related to session encryption.

WanWizard commented 7 months ago

Updated Crypt to use PHPSecLib 3.

Thanks for reporting it.