CVE-2021-28254: Critical severity laravel framework vulnerability
Published Apr 18, 2023
·Updated
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
Affected Software
1 affected component
Laravel Laravel=8.5.9
Event History
Apr 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28254?
CVE-2021-28254 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2021-28254?
To fix CVE-2021-28254, upgrade Laravel to a version later than 8.5.9.
3
What kind of attack is possible with CVE-2021-28254?
CVE-2021-28254 allows attackers to exploit a deserialization vulnerability to execute arbitrary commands on the server.
4
Which versions of Laravel are affected by CVE-2021-28254?
CVE-2021-28254 specifically affects Laravel version 8.5.9.
5
Is CVE-2021-28254 related to data integrity?
Yes, CVE-2021-28254 impacts data integrity by potentially allowing unauthorized command execution, altering application behavior.