CVE-2022-40482
Last modified
CVE-2022-40482 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Laravel | Framework | >= 8.0.0, < 8.83.24 |
| Laravel | Framework | >= 9.0.0, < 9.32.0 |
References
- https://ephort.dk/blog/laravel-timing-attack-vulnerability/Exploit, Technical Description, Third Party Advisory
- https://github.com/ephort/laravel-user-enumeration-demoExploit, Third Party Advisory
- https://github.com/laravel/framework/pull/44069Patch, Vendor Advisory
- https://ephort.dk/blog/laravel-timing-attack-vulnerability/Exploit, Technical Description, Third Party Advisory
- https://github.com/ephort/laravel-user-enumeration-demoExploit, Third Party Advisory
- https://github.com/laravel/framework/pull/44069Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-40482?
How severe is CVE-2022-40482?
How do I fix CVE-2022-40482?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-40471Remote Code Execution in Clinic's Patient Management System …9.8
- CVE-2022-40472ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build:…8
- CVE-2022-40475TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to con…9.8
- CVE-2022-40476A null pointer dereference issue was discovered in fs/io_uri…5.5
- CVE-2022-4048Inadequate Encryption Strength in CODESYS Development System…7.7
- CVE-2022-40480Nordic Semiconductor, Microchip Technology NRF5340-DK DT1001…6.5
- CVE-2022-40483Wedding Planner v1.0 was discovered to contain a SQL injecti…9.8
- CVE-2022-40484Wedding Planner v1.0 was discovered to contain a SQL injecti…9.8
- CVE-2022-40485Wedding Planner v1.0 was discovered to contain a SQL injecti…9.8
- CVE-2022-40486TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401…8.8
- CVE-2022-40487ProcessWire v3.0.200 was discovered to contain multiple cros…6.1
- CVE-2022-40488ProcessWire v3.0.200 was discovered to contain a Cross-Site …6.5
Are you affected by CVE-2022-40482?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
