The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-11-17T19:17:55

Updated: 2021-11-17T19:17:55

Reserved: 2021-11-17T00:00:00


Link: CVE-2021-43996

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-11-17T20:15:10.677

Modified: 2023-08-08T14:21:49.707


Link: CVE-2021-43996

JSON object: View

cve-icon Redhat Information

No data.