RFC: Don't automatically unserialize Phar metadata outside getMetadata()

Project Governance
Author
Target
8.0
In 2018, various vulnerabilities were found in php web frameworks due to the phar stream wrappers. A call such as file_exists("phar://...somepath.extension/file...

Stop automatically unserializing Phar metadata outside direct getMetadata() calls

Overall Results

Yes
No
Yes
25 Votes (100%)
No
0 Votes (0%)

Voting Timeline

Dates based on UTC

Voting Breakdown