CVE-2021-43996: Critical severity laravel ignition vulnerability
Published Nov 17, 2021
·Updated
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
Affected Software
4 affected componentsFixes available
composer/facade/ignition>=2.0.0<2.0.6
2.0.6
composer/facade/ignition<1.16.15
1.16.15
Facade Ignition Laravel<1.6.15
Facade Ignition Laravel>=2.0.0<2.0.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 17, 2021
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Nov 19, 2021
Advisory Published
08:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-43996?
CVE-2021-43996 has a high severity rating due to its potential impact on access control.
2
How do I fix CVE-2021-43996?
To fix CVE-2021-43996, update the Ignition component to version 1.16.15 or 2.0.6 or newer.
3
What versions are affected by CVE-2021-43996?
CVE-2021-43996 affects Ignition component versions prior to 1.16.15 and 2.0.x prior to 2.0.6.
4
What software is impacted by CVE-2021-43996?
CVE-2021-43996 impacts the Facade Ignition component used within Laravel applications.
5
What functionality does CVE-2021-43996 exploit?
CVE-2021-43996 exploits the 'fix variable names' feature that may result in incorrect access control.