Skip to main content

CVE detail

CVE-2021-3129

Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

CVSS 9.8 · CriticalBuzz score 57.4KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 57.4

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 5.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
5.0
1 repos · best confidence 0.99
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • CRYSTALRAY, a threat actor known to have used Secure Shell (SSH) based malware to gain access into victim systems in the past, has scaled operations to over 1,500 victims using multiple open source software (OSS) tools, according to a Sysdig study. After gaining access, the threat actor installs backdoors to maintain control and uses SSH-Snake […]

    newswww.csoonline.comJul 12, 2024, 10:56 AM
  • A threat actor known as CrystalRay targeted 1,500 victims since February using tools like SSH-Snake and various open-source utilities. The Sysdig Threat Research Team (TRT) first spotted the threat actor CrystalRay on February 2024 and observed it using the SSH-Snake open-source software penetration testing tool. The experts collected new evidence that revealed that the threat actor expanded its operations. […]

    newssecurityaffairs.comJul 11, 2024, 8:45 PM
  • A threat actor tracked as CrystalRay has hit 1,500 victims since February, stealing credentials and deploying backdoors.

    newswww.securityweek.comJul 11, 2024, 2:26 PM
  • A threat research team (TRT) of cloud security software provider Sysdig, has discovered a Romania-based ransomware group, which it now tracks as Rubycarp, that has been active for a decade. The threat actor, as discovered by Sysdig, operates primarily by deploying a botnet using a variety of public exploits and brute force attacks. “This group […]

    newswww.csoonline.comApr 9, 2024, 2:05 PM
  • Hackers have found a new way to abuse cloud computing accounts by spawning virtual machines to join a blockchain-based content delivery. This allows them to potentially bypass limitations put in place by admins to prevent cryptocurrency mining because the focus is not on CPU cycles and RAM but rather on storage space and bandwidth. Researchers […]

    newswww.csoonline.comMar 13, 2024, 5:56 PM
  • CISA says Owl Labs video conferencing device vulnerabilities that require the attacker to be in close range exploited in attacks

    newswww.securityweek.comSep 19, 2023, 10:00 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 0 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2021-28254

    A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary commands.

    CVSS 9.8 · Critical
  • CVE-2022-2886

    A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipulation leads to deserialization. It is possible to launch t…

    CVSS 5.0 · Medium
  • CVE-2022-2870

    A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The manipulation leads to deserialization. The attack may be in…

    CVSS 4.1 · Medium
  • CVE-2021-43996

    The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.

    CVSS 9.8 · Critical
  • CVE-2021-21263

    Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a query binding exploitation. This same exploit applies to the illuminate/dat…

    CVSS 7.2 · High
  • CVE-2020-24941

    An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting express…

    CVSS 7.5 · High