Remote Attack May Expose Database Credentials in Laravel Logs
CVE-2024-29291

Currently unrated

Key Information:

Vendor
CVE Published:
16 April 2024

What is CVE-2024-29291?

An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.

References

Timeline

  • Vulnerability published

.
CVE-2024-29291 : Remote Attack May Expose Database Credentials in Laravel Logs