CVE-2021-3129: Laravel Arbitrary Code Vulnerability Alert
Ignition is a beautiful and customizable error page for Laravel applications running on Laravel 5.5 and newer. It is the default error page for all Laravel 6 applications. It also allows to publicly share your errors on Flare. If configured with a valid Flare API key, your errors in production applications will be tracked, and you’ll get notified when they happen.
Vulnerability Detail
Affected version
- Laravel < 8.4.3
- Facade ignition < 2.5.2
Solution
The latest security patch has been officially released. It is recommended that affected users upgrade the Laravel framework to 8.4.3 and above, or upgrade the Facade Ignition component to 2.5.2 and above