Skip to content

Conversation

@erikn69
Copy link
Contributor

@erikn69 erikn69 commented Mar 13, 2024

On redis driver, cache comes serialized
image
After unserialize
image

@barryvdh
Copy link
Owner

barryvdh commented May 9, 2025

Hmmm I'm not a fan of unserialize. Are we 100% sure the value is serialized by the driver? Because otherwise a string posing as a serialized string could lead to issues (eg https://www.invicti.com/blog/web-security/untrusted-data-unserialize-php/ and more)

@erikn69
Copy link
Contributor Author

erikn69 commented May 9, 2025

then it is better not to risk it

@erikn69 erikn69 closed this May 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants