Описание
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
Ссылки
- Issue TrackingMailing ListThird Party Advisory
- Release NotesThird Party Advisory
- Issue TrackingVendor Advisory
- Issue TrackingMailing ListThird Party Advisory
- Release NotesThird Party Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.5.9 (включая)
cpe:2.3:a:laravel:laravel:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00289
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.9
debian
больше 7 лет назад
Laravel before 5.5.10 mishandles the remember_me token verification pr ...
EPSS
Процентиль: 52%
0.00289
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200