Junglewise Threat Intelligence

CVE-2024-51758: Filament insecure default storage for exported files

CVE-2024-51758 · Severity: low · CVSS 3.1 · Published 2024-11-07

Vendors: Filament, Packagist.

Executive brief

Filament is an open-source UI framework for Laravel applications. A vulnerability exists where data exported by users is stored in a publicly accessible folder by default. This could allow unauthorized individuals to access sensitive exported information if the application's storage settings are not manually hardened.

Technical details

Filament (specifically the filament/actions package) uses an insecure default configuration for its export feature. By default, the 'default_filesystem_disk' is set to 'public', which causes exported files—often containing sensitive data—to be stored in a web-accessible directory. While many production environments use S3 or other secure drivers, installations relying on the default local 'public' disk are vulnerable to information disclosure. An attacker with network access could potentially discover and download these exported files. The fix, introduced in version 3.2.123, automatically swaps the export disk to 'local' if 'public' is detected as the default.

Affected products

  • Filament filament/actions >= 3.2.0, < 3.2.123

Timeline

  • 2024-11-07: disclosed
  • 2024-11-07: advisory
  • 2024-11-07: patched

References