Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-40482

Опубликовано: 25 апр. 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.83.24 (исключая)
cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.32.0 (исключая)

EPSS

Процентиль: 53%
0.00298
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-203

Связанные уязвимости

CVSS3: 5.3
github
почти 3 года назад

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

EPSS

Процентиль: 53%
0.00298
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-203