CVE-2021-3129
Laravel Ignition File Upload Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 9 October 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.94% probability · 100th percentile
- CISA KEV
- Listed 18 September 2023 · due 9 October 2023 · used in ransomware campaigns
- Affected
- facade/ignition
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://github.com/facade/ignition/releases/tag/2.5.2; https://nvd.nist.gov/vuln/detail/CVE-2021-3129
References
- http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/facade/ignition/pull/334Patch, Third Party Advisory
- https://www.ambionics.io/blog/laravel-debug-rceExploit, Third Party Advisory
- http://packetstormsecurity.com/files/162094/Ignition-2.5.1-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165999/Ignition-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/facade/ignition/pull/334Patch, Third Party Advisory
- https://www.ambionics.io/blog/laravel-debug-rceExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-3129US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.