UnserializeExploits
error on by defaultGroup: Security · PhpStorm name: UnserializeExploitsInspection
unserialize() on attacker-controlled data can instantiate arbitrary classes (PHP object injection). Report calls whose input can be traced to request data or raw decoders, and — on PHP 7+ — calls that do not restrict the allowed classes.
Example
At PHP 5.6:
php
<?php
class Inbox
{
public function load($path)
{
$data = file_get_contents($path);
$data = gzinflate($data);
return unserialize($data);
}
public function fromRequest()
{
$packed = $_POST['state']['blob'];
$packed = $_COOKIE['state'];
return unserialize($packed);
}
public function fromSession()
{
return unserialize($_SESSION['cart']);
}
public function permissive($s)
{
return unserialize($s, TRUE);
}
}Reported:
- line 8: Untrusted data may reach unserialize() via: file_get_contents(...).
- line 15: Untrusted data may reach unserialize() via: $_COOKIE, $_POST.
- line 25: Restrict the classes unserialize() may create via its second argument.
Configure
In custos.json:
json
{
"rules": {
"UnserializeExploits": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore UnserializeExploits
/**
* @noinspection UnserializeExploitsInspection
*/