Exploited· due 2024-02-06
CVE-2018-15133
Laravel Laravel Framework
Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the application encryption key (APP_KEY environment variable).
Exploitation status
- CISA has confirmed this is being exploited in the wild. That is an observation of real attacks, not a prediction.
- US federal civilian agencies are required to remediate it by 2024-02-06. That deadline does not bind private companies, but it is a reasonable benchmark for how urgently CISA views it.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA’s wording, unedited.
Scoring
- CVSS
- Not yet scored
Dates
- Published
- 2024-01-16
- Added to KEV
- 2024-01-16
- Remediation due
- 2024-02-06
- Sources
- CISA KEV