SCA: security update for illuminate/database, laravel/framework (GHSA-3p32-j457-pg5x)

medium Tenable Cloud Security Plugin ID 409602

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Laravel is a web application framework. Versions of Laravel before 6.20.11, 7.30.2 and 8.22.1 contain a
query binding exploitation. This same exploit applies to the illuminate/database package which is used by
Laravel. If a request is crafted where a field that is normally a non-array value is an array, and that
input is not validated or cast to its expected type before being passed to the query builder, an
unexpected number of query bindings can be added to the query. In some situations, this will simply lead
to no results being returned by the query builder; however, it is possible certain queries could be
affected in a way that causes the query to return unexpected results. (CVE-2021-21263)

See Also

https://github.com/advisories/GHSA-3p32-j457-pg5x

Plugin Details

Severity: Medium

ID: 409602

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-21263

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/19/2021

Vulnerability Publication Date: 1/19/2021

Reference Information

CVE: CVE-2021-21263