VDB
Sign up
CRITICAL9.8

GHSA-4qwp-7c67-jmcc

Unauthenticated remote code execution in Ignition

Quick fix

GHSA-4qwp-7c67-jmcc — facade/ignition: upgrade to the fixed version with the command below.

composer require facade/ignition:^2.5.2

Details

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/facade/ignition
Introduced in: 2.5.0Fixed in: 2.5.2
Fixcomposer require facade/ignition:^2.5.2
Packagist/facade/ignition
Introduced in: 2.0.0Fixed in: 2.4.2
Fixcomposer require facade/ignition:^2.4.2
Packagist/facade/ignition
Introduced in: 1.7.0Fixed in: 1.16.14
Fixcomposer require facade/ignition:^1.16.14
Packagist/facade/ignition
Introduced in: 0Fixed in: 1.6.15
Fixcomposer require facade/ignition:^1.6.15

References