CVE record
CVE-2021-3129
Laravel Ignition File Upload Vulnerability
Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
critical
CVSS 9.8 ยท CVSS_V3
Affected packages
1
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Laravel
- Product
- Ignition
- Date added
- Sep 18, 2023
- CISA federal remediation due date
- Oct 9, 2023
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Known ransomware campaign use
- Known
- CWE
- Not supplied
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| facade/ignition | composer | 2.5.2, 2.4.2, 1.16.14, 1.6.15 |