Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fjv-25q9-2w88

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью

Описание

State Guessing Vulnerability in laravel/socialite

laravel/socialite versions prior to 2.0.10 are susceptible to a security vulnerability related to state guessing during OAuth authentication. This vulnerability could potentially lead to session hijacking, allowing attackers to compromise user sessions. The issue has been addressed and fixed in version 2.0.10.

Пакеты

Наименование

laravel/socialite

composer
Затронутые версииВерсия исправления

>= 1.0.0, < 2.0.10

2.0.10