Lucene search

K
cvelistMitreCVELIST:CVE-2022-40482
HistoryApr 25, 2023 - 12:00 a.m.

CVE-2022-40482

2023-04-2500:00:00
mitre
www.cve.org
2
cve-2022-40482
laravel
user enumeration
timeless timing attacks
http/2 multiplexing
illuminate\auth\sessionguard class

EPSS

0.001

Percentile

46.5%

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

EPSS

0.001

Percentile

46.5%

Related for CVELIST:CVE-2022-40482