Disable Laravel Ignition in production
tech-laravel-ignition
Ignition's debug endpoint has been used for remote code execution (CVE-2021-3129). Set APP_DEBUG to false and keep it out of production builds.
Why this matters
Laravel Ignition's debug endpoint is exposed. This can execute arbitrary code on your server (CVE-2021-3129). Set APP_DEBUG=false in production.
Frameworks
Laravel
- 1 Set APP_DEBUG=false in your .env file
- 2 Remove or disable the Ignition package in production
- 3 Verify the change with: php artisan env
bash
# In .env
APP_DEBUG=false
APP_ENV=productionDoes your app still have this?
Scan your domain