📦

ignition

Vendor: facade

Actively Exploited 1 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 31.75% Exploit Prob.
Latest CVE CVE-2021-43996 Nov 17

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

EPSS: 0.53%
Critical Target
9.8 CVSS
CVE-2021-3129
RCE Exploit Found

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

EPSS: 94.29%
9.8 CVSS

The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.

EPSS: 0.43%