Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
LaravelのCVE-2021-3129の脆弱性について.pdf
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
noviiro
November 05, 2023
360
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
LaravelのCVE-2021-3129の脆弱性について.pdf
noviiro
November 05, 2023
More Decks by noviiro
See All by noviiro
My GAS Tips
noviiro
1
330
LWWSxGASxSlack
noviiro
0
320
FileMaker Data API
noviiro
0
200
Tried to set up Mastodon instance for myself. ( ja )
noviiro
0
200
Several TIPS for making a single board computer a web server (ja)
noviiro
0
260
PINE64で遊んでみた
noviiro
0
430
Featured
See All Featured
Sam Torres - BigQuery for SEOs
techseoconnect
PRO
0
560
Conquering PDFs: document understanding beyond plain text
inesmontani
PRO
4
3.1k
BBQ
matthewcrist
89
10k
SEOcharity - Dark patterns in SEO and UX: How to avoid them and build a more ethical web
sarafernandez
0
290
Data-driven link building: lessons from a $708K investment (BrightonSEO talk)
szymonslowik
1
1.3k
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
470
How to optimise 3,500 product descriptions for ecommerce in one day using ChatGPT
katarinadahlin
PRO
3
3.8k
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
31
3.4k
The AI Search Optimization Roadmap by Aleyda Solis
aleyda
1
6.3k
Leveraging LLMs for student feedback in introductory data science courses - posit::conf(2025)
minecr
1
410
Darren the Foodie - Storyboard
khoart
PRO
4
4k
Claude Code のすすめ
schroneko
67
230k
Transcript
LaravelのCVE-2021-3129の 脆弱性について Gunma.web #51 ‘23 11/04 @noviiro
CVE-2021-3129の脆弱性について • https://nvd.nist.gov/vuln/detail/CVE-2021-3129 • Laravel 8.4.2(Ignition 2.5.1)の古い構成 • APP_DEBUG=trueの状態で有効 •
上記脆弱性により、第三者にHPの公開ディレクトリにデバッグモードでアクセス され、curlを使ったファイルの設置と実行ができる状態になる。
APP_DEBUG=true について • Laravelでは.envファイルの設定が優先 ◦ /config/app.phpなどでfalseにしていても、そもそもの .envファイルでtrueになっていればそれが 優先される。 再現環境
おさらい • 使用しているフレームワークの脆弱性情報は常にキャッチアップする ◦ JVNやNVDなど ◦ https://nvd.nist.gov/developers/vulnerabilities APIで叩ける。 ◦ VulsやFuture
Vulsなど、脆弱性スキャナを webサーバーに設置して定期的にスキャンするのも 手。(Vulsに関してはIPAも紹介している)
おさらい 2 • WAFの選定は重要。ゼロデイ攻撃でもふるまい検知等でWAFで防げるように選 定・構築をする(IP直のアクセスも防げる契約を選ぼう)