CVE-2017-16894 describes an information disclosure vulnerability in Laravel framework versions through 5.5.21, allowing remote attackers to retrieve sensitive data like passwords by directly requesting the /.env file. This flaw stems from the writeNewEnvironmentFileWith function not properly restricting .env file permissions. The vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity and high confidentiality impact. While not listed in CISA's KEV catalog, exploit intelligence shows available Metasploit modules and Nuclei templates, suggesting potential for exploitation despite limited public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.5.21CPE matchmatch criteria | cpe:2.3:a:laravel:laravel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.