An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| tecnickcom/tcpdf(Packagist) | 0 | 6.2.22 | N/A |
| fooman/tcpdf(Packagist) | 0 | 6.2.22 | N/A |
| la-haute-societe/tcpdf(Packagist) | 0 | 6.2.22 | N/A |
| spoonity/tcpdf(Packagist) | 0 | 6.2.22 | N/A |
CVSS Metrics