Critical severity vulnerability in Ignition
Critical severity
GitHub Reviewed
Published
Oct 12, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
>= 2.0.0, < 2.0.5
< 1.16.15
Patched versions
2.0.5
1.16.15
Description
Published by the National Vulnerability Database
Jun 7, 2020
Reviewed
Oct 8, 2021
Published to the GitHub Advisory Database
Oct 12, 2021
Last updated
Feb 1, 2023
The Ignition page before version 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env.
NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.
References