PT-2021-23998 · Laravel · Laravel Ignition

Published

2021-11-17

·

Updated

2023-08-08

·

CVE-2021-43996

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Laravel Ignition component versions prior to 1.16.15 Laravel Ignition component versions 2.0.x prior to 2.0.6
Description: The issue concerns the "fix variable names" feature in the Ignition component for Laravel, which can lead to incorrect access control.
Recommendations: For versions prior to 1.16.15, update to version 1.16.15 or later. For versions 2.0.x prior to 2.0.6, update to version 2.0.6 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2021-43996
GHSA-VHRP-8QX4-VR6C

Affected Products

Laravel Ignition