CVE-2019-17050
Last modified
CVE-2019-17050 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thecontrolgroup | Voyager | <= 1.2.7 |
References
- https://github.com/the-control-group/voyager/issues/4322Third Party Advisory
- https://github.com/the-control-group/voyager/issues/4322Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-17050?
How severe is CVE-2019-17050?
How do I fix CVE-2019-17050?
Are you affected by CVE-2019-17050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
