Junglewise Threat Intelligence

CVE-2021-3129: Unauthenticated remote code execution in Ignition

CVE-2021-3129 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-03-29

Technologies: Facade Ignition, Laravel. Vendors: Laravel.

Executive brief

Ignition before 2.5.2, as used in Laravel and other products, contains a file upload vulnerability due to insecure usage of file_get_contents() and file_put_contents(). Unauthenticated remote attackers can exploit this on sites using debug mode to execute arbitrary code.

Affected products

  • Facade Ignition < 2.5.2
  • Laravel Laravel < 8.4.2

Timeline

  • 2021-01-20: disclosed: Initial NVD analysis date
  • 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-18: advisory