{"id":"CVE-2021-43617","details":"Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.","modified":"2026-07-09T05:45:31.467849Z","published":"2021-11-14T16:15:08.610Z","references":[{"type":"ADVISORY","url":"https://github.com/laravel/framework/blob/2049de73aa099a113a287587df4cc522c90961f5/src/Illuminate/Validation/Concerns/ValidatesAttributes.php#L1331-L1333"},{"type":"FIX","url":"https://salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.conf#L5-6"},{"type":"FIX","url":"https://salsa.debian.org/php-team/php/-/commit/dc253886b5b2e9bc8d9e36db787abb083a667fd8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/laravel/framework","events":[{"introduced":"0"},{"last_affected":"dec9524cd0f9fa35a6eb8e25d0b40f8bbc8ec225"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"8.70.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*"}}],"versions":["v8.70.2","v8.70.1","v8.70.0","v8.68.0","v8.67.0","v8.66.0","v8.65.0","v8.64.0","v8.63.0","v8.62.0","v8.61.0","v8.60.0","v8.59.0","v8.58.0","v8.57.0","v8.56.0","v8.55.0","v8.54.0","v8.53.1","v8.53.0","v8.52.0","v8.51.0","v8.50.0","v8.49.2","v8.49.1","v8.49.0","v8.48.2","v8.48.1","v8.48.0","v8.47.0","v8.46.0","v8.45.1","v8.45.0","v8.44.0","v8.43.0","v8.42.1","v8.42.0","v8.41.0","v8.40.0","v8.38.0","v8.36.0","v8.35.1","v8.35.0","v8.33.0","v8.32.1","v8.32.0","v8.31.0","v8.30.0","v8.30.1","v8.29.0","v8.28.1","v8.28.0","v8.27.0","v8.26.1","v8.26.0","v8.25.0","v8.24.0","v8.23.1","v8.23.0","v8.22.1","v8.22.0","v8.21.0","v8.20.1","v8.20.0","v8.19.0","v8.17.2","v8.17.1","v8.17.0","v8.16.0","v8.15.0","v8.14.0","v8.13.0","v8.12.3","v8.12.2","v8.12.1","v8.12.0","v8.11.2","v8.11.0","v8.11.1","v8.9.0","v8.8.0","v8.7.1","v8.7.0","v8.6.0","v8.5.0","v8.4.0","v8.3.0","v8.2.0","v8.1.0","v8.0.4","v8.0.3","v8.0.2","v8.0.1","v8.0.0","v5.5.1","v5.5.0","v4.1.0","v4.0.0","v4.0.0-BETA4","v4.0.0-BETA3","v4.0.0-BETA2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43617.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}