PT-2020-15864 · Taylor Otwell · Laravel

Published

2020-09-04

·

Updated

2024-03-06

·

CVE-2020-24941

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Laravel versions prior to 6.18.35 Laravel versions 7.x prior to 7.24.0
Description An issue was discovered in Laravel where the $guarded property is mishandled in certain situations involving requests with JSON column nesting expressions.
Recommendations For Laravel versions prior to 6.18.35, update to version 6.18.35 or later. For Laravel versions 7.x prior to 7.24.0, update to version 7.24.0 or later.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-LARAVEL-2020-24941
CVE-2020-24941
GHSA-W68R-5P45-5RQP

Affected Products

Laravel