Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Laravel 安全漏洞
Vulnerability Description
Laravel是Laravel社区的一个Web 应用程序框架。 Laravel 8.x版本至9.x版本至9.32.0之前版本存在安全漏洞,该漏洞源于身份验证方法被发现容易受到攻击。
CVSS Information
N/A
Vulnerability Type
N/A