SCA: security update for illuminate/view, laravel/framework (GHSA-66hf-2p6w-jqfw)

medium Tenable Cloud Security Plugin ID 411243

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a
possible cross-site scripting (XSS) vulnerability in the Blade templating engine. A broken HTML element
may be clicked and the user taken to another location in their browser due to XSS. This is due to the user
being able to guess the parent placeholder SHA-1 hash by trying common names of sections. If the parent
template contains an exploitable HTML structure an XSS vulnerability can be exposed. This vulnerability
has been patched in versions 8.75.0, 7.30.6, and 6.20.42 by determining the parent placeholder at runtime
and using a random hash that is unique to each request. (CVE-2021-43808)

See Also

https://github.com/advisories/GHSA-66hf-2p6w-jqfw

Plugin Details

Severity: Medium

ID: 411243

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 8.67

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.4

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-43808

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/8/2021

Vulnerability Publication Date: 12/7/2021

Reference Information

CVE: CVE-2021-43808