Lucene search

K
cve[email protected]CVE-2021-21979
HistoryMar 03, 2021 - 5:15 p.m.

CVE-2021-21979

2021-03-0317:15:12
CWE-798
web.nvd.nist.gov
26
bitnami
containers
laravel
cve-2021-21979
security
vulnerability
encryption
php
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%

In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and the value of APP_KEY is fixed under certain conditions. This value is crucial for the security of the application and must be randomly generated per Laravel installation. If your application’s encryption key is in the hands of a malicious party, that party could craft cookie values using the encryption key and exploit vulnerabilities inherent to PHP object serialization / unserialization, such as calling arbitrary class methods within your application.

Affected configurations

NVD
Node
bitnamicontainersRange6.0.2-debian-9-r06.0.2-debian-9-r22laravel
OR
bitnamicontainersRange6.4.0-debian-9-r06.4.0-debian-9-r31laravel
OR
bitnamicontainersRange6.5.2-debian-9-r06.5.2-debian-9-r20laravel
OR
bitnamicontainersRange6.8.0-debian-9-r06.8.0-debian-9-r26laravel
OR
bitnamicontainersRange6.12.0-debian-9-r06.12.0-debian-10-r33laravel
OR
bitnamicontainersRange6.18.0-debian-10-r06.18.0-debian-10-r21laravel
OR
bitnamicontainersRange6.18.3-debian-10-r06.18.3-debian-10-r22laravel
OR
bitnamicontainersRange6.18.8-debian-10-r06.18.8-debian-10-r110laravel
OR
bitnamicontainersRange6.18.35-debian-10-r06.18.35-debian-10-r66laravel
OR
bitnamicontainersRange6.20.0-debian-10-r06.20.0-debian-10-r107laravel
OR
bitnamicontainersRange7.0.0-debian-10-r07.0.0-debian-10-r7laravel
OR
bitnamicontainersRange7.3.0-debian-10-r07.3.0-debian-10-r20laravel
OR
bitnamicontainersRange7.6.0-debian-10-r07.6.0-debian-10-r38laravel
OR
bitnamicontainersRange7.12.0-debian-10-r07.12.0-debian-10-r72laravel
OR
bitnamicontainersRange7.25.0-debian-10-r07.25.0-debian-10-r16laravel
OR
bitnamicontainersRange7.28.0-debian-10-r07.28.0-debian-10-r50laravel
OR
bitnamicontainersRange7.30.1-debian-10-r07.30.1-debian-10-r108laravel
OR
bitnamicontainersRange8.0.1-debian-10-r08.0.1-debian-10-r7laravel
OR
bitnamicontainersRange8.0.3-debian-10-r08.0.3-debian-10-r18laravel
OR
bitnamicontainersRange8.1.0-debian-10-r08.1.0-debian-10-r7laravel
OR
bitnamicontainersRange8.2.0-debian-10-r08.2.0-debian-10-r8laravel
OR
bitnamicontainersRange8.4.0-debian-10-r08.4.0-debian-10-r10laravel
OR
bitnamicontainersRange8.4.1-debian-10-r08.4.1-debian-10-r6laravel
OR
bitnamicontainersRange8.4.2-debian-10-r08.4.2-debian-10-r4laravel
OR
bitnamicontainersRange8.4.3-debian-10-r08.4.3-debian-10-r6laravel
OR
bitnamicontainersRange8.4.4-debian-10-r08.4.4-debian-10-r6laravel
OR
bitnamicontainersRange8.5.5-debian-10-r08.5.5-debian-10-r11laravel
OR
bitnamicontainersRange8.5.6-debian-10-r08.5.6-debian-10-r13laravel
OR
bitnamicontainersRange8.5.7-debian-10-r08.5.7-debian-10-r6laravel
OR
bitnamicontainersRange8.5.8-debian-10-r08.5.8-debian-10-r5laravel
OR
bitnamicontainersRange8.5.9-debian-10-r08.5.9-debian-10-r25laravel
OR
bitnamicontainersRange8.5.10-debian-10-r08.5.10-debian-10-r6laravel
OR
bitnamicontainersMatch6.19.0-debian-10-r0laravel
OR
bitnamicontainersMatch7.29.0-debian-10-r0laravel
OR
bitnamicontainersMatch7.30.0-debian-10-r0laravel
OR
bitnamicontainersMatch8.3.0-debian-10-r0laravel
OR
bitnamicontainersMatch8.5.2-debian-10-r0laravel
OR
bitnamicontainersMatch8.5.2-debian-10-r1laravel
OR
bitnamicontainersMatch8.5.3-debian-10-r0laravel
OR
bitnamicontainersMatch8.5.4-debian-10-r0laravel
OR
bitnamicontainersMatch8.5.4-debian-10-r1laravel

CNA Affected

[
  {
    "product": "Bitnami Containers",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6,  7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8"
      }
    ]
  }
]

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.8%

Related for CVE-2021-21979