CVE detail
CVE-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 5.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
CRYSTALRAY, a threat actor known to have used Secure Shell (SSH) based malware to gain access into victim systems in the past, has scaled operations to over 1,500 victims using multiple open source software (OSS) tools, according to a Sysdig study. After gaining access, the threat actor installs backdoors to maintain control and uses SSH-Snake […]
newswww.csoonline.comJul 12, 2024, 10:56 AM- CrystalRay operations have scaled 10x to over 1,500 victimsSecurity Affairs
A threat actor known as CrystalRay targeted 1,500 victims since February using tools like SSH-Snake and various open-source utilities. The Sysdig Threat Research Team (TRT) first spotted the threat actor CrystalRay on February 2024 and observed it using the SSH-Snake open-source software penetration testing tool. The experts collected new evidence that revealed that the threat actor expanded its operations. […]
newssecurityaffairs.comJul 11, 2024, 8:45 PM A threat actor tracked as CrystalRay has hit 1,500 victims since February, stealing credentials and deploying backdoors.
newswww.securityweek.comJul 11, 2024, 2:26 PMA threat research team (TRT) of cloud security software provider Sysdig, has discovered a Romania-based ransomware group, which it now tracks as Rubycarp, that has been active for a decade. The threat actor, as discovered by Sysdig, operates primarily by deploying a botnet using a variety of public exploits and brute force attacks. “This group […]
newswww.csoonline.comApr 9, 2024, 2:05 PMHackers have found a new way to abuse cloud computing accounts by spawning virtual machines to join a blockchain-based content delivery. This allows them to potentially bypass limitations put in place by admins to prevent cryptocurrency mining because the focus is not on CPU cycles and RAM but rather on storage space and bandwidth. Researchers […]
newswww.csoonline.comMar 13, 2024, 5:56 PMCISA says Owl Labs video conferencing device vulnerabilities that require the attacker to be in close range exploited in attacks
newswww.securityweek.comSep 19, 2023, 10:00 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.99 · max 0 stars
- theNareshofficial/CVE-2021-3129-LabHigh confidencegithubRepository topic discovery0 starsDiscovered Jul 18, 2026, 8:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-28254CVSS 9.8 · Critical
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.
- CVE-2022-2886CVSS 5.0 · Medium
A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch t…
- CVE-2022-2870CVSS 4.1 · Medium
A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be in…
- CVE-2021-43996CVSS 9.8 · Critical
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
- CVE-2021-21263CVSS 7.2 · High
Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/dat…
- CVE-2020-24941CVSS 7.5 · High
An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting express…