PT-2023-13792 · Laravel · Laravel
Jens Ji
·
Publicado
2023-04-25
·
Atualizado
2025-02-03
·
CVE-2022-40482
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Laravel versions 8.x through 9.x before 9.32.0
Description
The authentication method was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This issue is caused by the early return inside the
hasValidCredentials method in the IlluminateAuthSessionGuard class when a user is found to not exist.Recommendations
For Laravel versions 8.x through 9.x before 9.32.0, update to version 9.32.0 or later to resolve the issue. As a temporary workaround, consider modifying the
hasValidCredentials method in the IlluminateAuthSessionGuard class to prevent early returns that could reveal user existence.Exploit
Correção
Side Channel Attack
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Laravel