7.3
CVSSv3

CVE-2021-21979

Published: 03/03/2021 Updated: 03/05/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.3 | Impact Score: 3.4 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/laravel was built, and the value of APP_KEY is fixed under certain conditions. This value is crucial for the security of the application and must be randomly generated per Laravel installation. If your application's encryption key is in the hands of a malicious party, that party could craft cookie values using the encryption key and exploit vulnerabilities inherent to PHP object serialization / unserialization, such as calling arbitrary class methods within your application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bitnami containers 8.5.4-debian-10-r1

bitnami containers 8.5.2-debian-10-r1

bitnami containers

bitnami containers 6.19.0-debian-10-r0

bitnami containers 7.29.0-debian-10-r0

bitnami containers 7.30.0-debian-10-r0

bitnami containers 8.3.0-debian-10-r0

bitnami containers 8.5.2-debian-10-r0

bitnami containers 8.5.3-debian-10-r0

bitnami containers 8.5.4-debian-10-r0

Github Repositories

The vulnerabilities i've found

my_vulnerabilities 1 Cloud Native Projects 11 bitnami/laravel 111 [DONE] CVE-2021-21979: APP_KEY is fixed in docker image bitnami/laravel Timeline: 2021-02-23 Reported to bitnami 2021-02-24 Fixed 2021-02-24 CVE number assigned DONE 12 meshery 121 [DONE] CVE-2021-31856: A Sql Injection in Meshery githubcom/ssst0n3/CVE-2021-31856 Timeline: 2021-04-20 Discovered