VDB
Sign up
MEDIUM6.1

GHSA-rc8x-jrrc-frfv

Laravel does not properly constrain the host portion of a password-reset URL

Quick fix

GHSA-rc8x-jrrc-frfv — laravel/laravel: upgrade to the fixed version with the command below.

composer require laravel/laravel:^5.4.22

Details

Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/laravel/laravel
Introduced in: 5.4.0Fixed in: 5.4.22
Fixcomposer require laravel/laravel:^5.4.22
Packagist/illuminate/auth
Introduced in: 5.3.0

No fixed version published yet for illuminate/auth (composer). Pin to a known-safe version or switch to an alternative.

Packagist/illuminate/auth
Introduced in: 5.4.0Fixed in: 5.4.22
Fixcomposer require illuminate/auth:^5.4.22
Packagist/laravel/framework
Introduced in: 5.3.0

No fixed version published yet for laravel/framework (composer). Pin to a known-safe version or switch to an alternative.

Packagist/laravel/framework
Introduced in: 5.4.0Fixed in: 5.4.22
Fixcomposer require laravel/framework:^5.4.22

References