CVE-2021-3129 is a critical remote code execution (RCE) vulnerability affecting Ignition versions prior to 2.5.2, notably when used with Laravel in debug mode before version 8.4.2. This flaw stems from insecure usage of file_get_contents() and file_put_contents(), allowing unauthenticated attackers to execute arbitrary code. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling full compromise of affected systems. It is actively exploited in the wild, including in known ransomware campaigns, with public exploit modules available for Metasploit and Nuclei, and significant community discussion and media coverage confirming its widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.2CPE matchmatch criteria | cpe:2.3:a:facade:ignition:*:*:*:*:*:laravel:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.