logo

CVE-2020-24940 illuminate/database

Package

Manager: composer
Name: illuminate/database
Vulnerable Version: >=5.5.0 <=5.5.44 || >=6.0.0 <6.18.34 || >=7.0.0 <7.23.2

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00261 pctl0.4925

Details

Guard bypass in Eloquent models affecting Laravel illuminate database component An issue was discovered in Laravel before 6.18.34 and 7.x before 7.23.2. Unvalidated values are saved to the database component in some situations in which table names are stripped during a mass assignment.

Metadata

Created: 2022-05-24T17:27:24Z
Modified: 2024-05-15T20:22:26Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c7rm-w2hj-x8g3/GHSA-c7rm-w2hj-x8g3.json
CWE IDs: []
Alternative ID: GHSA-c7rm-w2hj-x8g3
Finding: F274
Auto approve: 1