CVE-2021-43617

NameCVE-2021-43617
DescriptionLaravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1002728

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
php-laravel-framework (PTS)bullseye6.20.14+dfsg-2+deb11u1fixed
bookworm, sid8.83.26+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php-laravel-frameworksourcebullseye6.20.14+dfsg-2+deb11u1
php-laravel-frameworksource(unstable)6.20.14+dfsg-31002728

Notes

https://hosein-vita.medium.com/laravel-8-x-image-upload-bypass-zero-day-852bd806019b

Search for package or bug name: Reporting problems