VDB
EN
MEDIUM 4.2

GHSA-crmm-hgp2-wgrp

Laravel Framework: Temporary Signed URL Path Confusion

상세

A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement.

Under certain conditions, a generated temporary signed URL can be interpreted differently by the server than intended at signing time. This may cause requests to resolve to an unintended resource, and can prevent expiration from being enforced, allowing expired URLs to remain valid indefinitely.

### Impact - Expired temporary URLs may continue to be accepted - Requests may resolve to a different resource than the one that was signed - The upload variant may allow writes to reach an unintended destination

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Packagist / laravel/framework
최초 영향 버전: 13.0.0 수정 버전: 13.12.0
수정 composer require laravel/framework:^13.12.0
Packagist / laravel/framework
최초 영향 버전: 0 수정 버전: 12.61.1
수정 composer require laravel/framework:^12.61.1

참고