CVE-2020-13909: Critical severity laravel ignition vulnerability
Published Jun 7, 2020
·Updated
The Ignition component before 2.0.5 for Laravel mishandles globals, get, post, cookie, and env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.
Affected Software
2 affected components
Facade Ignition Laravel>=1.0.0<1.16.15
Facade Ignition Laravel>=2.0.0<2.0.5
Remediation
Patch Available
Event History
Jun 7, 2020
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13909?
CVE-2020-13909 has a severity rated as medium due to the improper handling of global variables.
2
How do I fix CVE-2020-13909?
To fix CVE-2020-13909, upgrade to Ignition version 2.0.5 or later.
3
Which versions of Ignition are affected by CVE-2020-13909?
Versions of Ignition prior to 2.0.5 and the 1.x series before 1.16.15 are affected by CVE-2020-13909.
4
What components are involved in CVE-2020-13909?
CVE-2020-13909 involves the Ignition component of Laravel which mishandles globals, specifically _get, _post, _cookie, and _env.
5
Is CVE-2020-13909 fixed in version 1.16.15 of Ignition?
Yes, version 1.16.15 and later of Ignition are unaffected due to a fix related to CVE-2021-43996.