{"id":"CVE-2021-43996","aliases":["GHSA-vhrp-8qx4-vr6c"],"url":"https://o3.security/vulnerability/CVE-2021-43996","summary":"Incorrect Access Control in Ignition","details":"The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a \"fix variable names\" feature that can lead to incorrect access control.","published":"2021-11-17T20:15:10.677Z","modified":"2026-07-08T23:58:16.793480Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"facade/ignition","fixedVersion":"1.16.15"},{"ecosystem":"Packagist","name":"facade/ignition","fixedVersion":"2.0.6"}],"fix":{"url":"https://github.com/facade/ignition/pull/285","label":"facade/ignition#285"},"references":[{"type":"FIX","url":"https://github.com/facade/ignition/compare/1.16.14...1.16.15"},{"type":"FIX","url":"https://github.com/facade/ignition/compare/2.0.5...2.0.6"},{"type":"FIX","url":"https://github.com/facade/ignition/pull/285"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T23:58:16.793480Z"}}