Authentication Vulnerability in Laravel Fortify by Laravel
CVE-2022-25838

8.1HIGH

Key Information:

Vendor

Laravel

Status
Vendor
CVE Published:
24 February 2022

What is CVE-2022-25838?

Laravel Fortify versions prior to 1.11.1 exhibit a flaw that allows for the reuse of tokens within a limited timeframe. This compromised implementation raises significant security concerns regarding the integrity of the Time-based One-Time Password (TOTP) mechanism, questioning its reliability in providing secure authentication. By exploiting this vulnerability, an attacker could potentially bypass security measures, leading to unauthorized access. It is crucial for users and developers to update to the latest version to mitigate this risk and enhance the overall security posture of their applications.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-25838 : Authentication Vulnerability in Laravel Fortify by Laravel