Ignition
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3129 | Cri | 0.86 | 9.8 | 1.00 | KEV | Jan 12, 2021 | Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2. | |
| CVE-2020-14520 | Hig | 0.49 | 7.5 | 0.01 | Jul 31, 2020 | The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13). | ||
| CVE-2022-1264 | Med | 0.44 | 6.8 | 0.01 | Jul 20, 2022 | The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code. | ||
| CVE-2022-1706 | Med | 0.00 | 6.5 | 0.01 | May 17, 2022 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is… |
- risk 0.86cvss 9.8epss 1.00
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
- risk 0.49cvss 7.5epss 0.01
The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13).
- risk 0.44cvss 6.8epss 0.01
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
- risk 0.00cvss 6.5epss 0.01
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…