Ignition
Facade · 3 CVEs
CVE-2021-43996
CRITICAL
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can…
Nov 17, 2021
CVE-2021-3129
KEV CRITICAL
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitr…
Jan 12, 2021
CVE-2020-13909
CRITICAL
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x se…
Jun 7, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-43996 | The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control. | CRITICAL | 1.73% | Nov 17, 2021 |
| CVE-2021-3129 KEV | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of fi… | CRITICAL | 99.94% | Jan 12, 2021 |
| CVE-2020-13909 | The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are una… | CRITICAL | 1.48% | Jun 7, 2020 |
Showing 1 to 3 of 3 CVEs