S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 11, 2024

CVE-2017-16894 Scanner

Detects 'Information Disclosure' vulnerability in Laravel framework affects v. through 5.5.21.

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
19
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-16894
7.5
CVSS

In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

Laravel framework is a popular open-source PHP web application framework used for developing efficient and secure web applications. It provides elegant syntax and tools needed for large, robust applications. Laravel is built to follow the Model-View-Controller architecture and offers built-in tools for routing, authentication, and handling requests. It is widely used by developers to create web applications that can scale with their business.

One of the vulnerabilities identified in Laravel framework is CVE-2017-16894. This vulnerability was identified in the writeNewEnvironmentFileWith function of the KeyGenerateCommand.php file in Laravel, which uses file_put_contents without restricting the .env permissions. This security flaw enables remote attackers to obtain sensitive information like externally usable passwords, by requesting the /.env URI directly. This vulnerability was present in Laravel through version 5.5.21.

Upon exploiting this vulnerability, attackers can gain access to sensitive information such as passwords or API keys, which can be used to steal confidential data, launch denial-of-service attacks, or even access the company's financial and customer data. It can pose a significant threat to the overall security of the web application, exposing it to cyberattacks and data breaches.

At s4e.io, we offer pro features that enable our clients to detect vulnerabilities in their digital assets quickly and efficiently. Our platform identifies vulnerabilities in web applications, network components, and system software by scanning for open ports, discovering system configurations, and testing for known vulnerabilities. We also provide detailed reports and analysis, helping companies to mitigate risks promptly and stay secure. Protect your web applications today with s4e.io.

 

REFERENCES

Solution Advice

To protect against CVE-2017-16894 vulnerability, developers can take the following precautions:

  • Conduct regular security audits and perform penetration testing on their web applications.
  • Implement server and application hardening techniques.
  • Regularly update the Laravel framework with the latest patches and security fixes.
  • Ensure that the sensitive information is not stored in the environment configuration file.
  • Limit access to .env files only to authorized personnel.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.