CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-43996

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0360%
EPSS Percentile12.11th
Published2021年11月17日
Last Modified2024年11月21日

Vulnerability Description

The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

Affected Platforms (CPE)

📦
Facade

Ignition

< 1.6.15
📦
Facade

Ignition

>= 2.0.0 and < 2.0.6

References & Advisories

関連する脆弱性情報

CVE-2021-43996 Detail & Impact Analysis | CVSS 9.8 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space