Описание
Multi-Factor Authentication issue in Laravel Fortify
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-25838
- https://github.com/laravel/fortify/issues/201
- https://github.com/laravel/fortify/issues/201#issuecomment-1009282153
- https://github.com/laravel/fortify/pull/357
- https://github.com/laravel/fortify/pull/358
- https://github.com/FriendsOfPHP/security-advisories/blob/master/laravel/fortify/CVE-2022-25838.yaml
- https://github.com/advisories/GHSA-6w4v-qr4m-97gg
Пакеты
Наименование
laravel/fortify
composer
Затронутые версииВерсия исправления
< 1.11.1
1.11.1
Связанные уязвимости
CVSS3: 8.1
nvd
почти 4 года назад
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.