VDB
Sign up
HIGH7.5

GHSA-c7rm-w2hj-x8g3

Guard bypass in Eloquent models affecting Laravel illuminate database component

Quick fix

GHSA-c7rm-w2hj-x8g3 — illuminate/database: upgrade to the fixed version with the command below.

composer require illuminate/database:^6.18.34

Details

An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database component in some situations in which table names are stripped during a mass assignment.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/illuminate/database
Introduced in: 5.5.0

No fixed version published yet for illuminate/database (composer). Pin to a known-safe version or switch to an alternative.

Packagist/illuminate/database
Introduced in: 6.0.0Fixed in: 6.18.34
Fixcomposer require illuminate/database:^6.18.34
Packagist/illuminate/database
Introduced in: 7.0.0Fixed in: 7.23.2
Fixcomposer require illuminate/database:^7.23.2

References