MEDIUM5.9
GHSA-c2v7-j5gq-wcq4
Laravel Sensitive Data Exposure
Quick fix
GHSA-c2v7-j5gq-wcq4 — laravel/framework: upgrade to the fixed version with the command below.
composer require laravel/framework:^5.5.10Details
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/laravel/framework
Introduced in:
0Fixed in: 5.5.10Fix
composer require laravel/framework:^5.5.10Packagist/illuminate/auth
Introduced in:
0Fixed in: 5.5.10Fix
composer require illuminate/auth:^5.5.10References
- https://nvd.nist.gov/vuln/detail/CVE-2017-14775[ADVISORY]
- https://github.com/laravel/framework/pull/21320[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/illuminate/auth/CVE-2017-14775.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/laravel/framework/CVE-2017-14775.yaml[WEB]
- https://github.com/laravel/framework/releases/tag/v5.5.10[WEB]
- https://laravel-news.com/laravel-v5-5-11[WEB]