Ignition

Vendor:

First CVE: Jun 7, 2020 · Active for 6 years

3
Total CVEs
More Total CVEs than 64% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
9.8
Avg CVSS
Higher Avg CVSS than 87% of tracked products
33.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ignition over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2020
6 years ago
Most Recent CVE
Nov 17, 2021
1,710 days ago

CVE Severity & Scoring

Ignition3 CVEs
All CVEs352,231 CVEs
Critical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and
Jan 12, 20219.899YESYES
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a conseque
Jun 7, 20209.832NONO
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
Nov 17, 20219.824NONO

Exploit Exposure

Signals from CVEs in this product scope (3 CVEs).

CISA KEV
1 CVE
33.3% of CVEs· 98th percentile
Metasploit
1 CVE
33.3% of CVEs· 98th percentile
Nuclei
1 CVE
33.3% of CVEs· 98th percentile
ExploitDB
1 CVE
33.3% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (3 CVEs).

Media Mentions

Signals from CVEs in this product scope (3 CVEs).

Top CNAs Publishing CVEs For Ignition

Versions

No cataloged versions.