CVE-2021-3129
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Laravel Ignition File Upload Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-30/7/2026
מוצרים מושפעים
facade: ignition; laravel: laravel
קישורים
- https://github.com/facade/ignition/pull/334 PatchThird Party Advisory
- https://github.com/facade/ignition/pull/334 PatchThird Party Advisory
- http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Executi… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
- https://www.ambionics.io/blog/laravel-debug-rce ExploitThird Party Advisory
- http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Executi… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
- https://www.ambionics.io/blog/laravel-debug-rce ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource