CVE-2022-40482

Source
https://cve.org/CVERecord?id=CVE-2022-40482
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-40482.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-40482
Published
2023-04-25T19:15:10.180Z
Modified
2026-04-10T04:50:45.476526Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.

References

Affected packages

Git / github.com/laravel/framework

Affected ranges

Type
GIT
Repo
https://github.com/laravel/framework
Events
Database specific
{
    "versions": [
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.83.24"
        },
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "9.32.0"
        }
    ]
}

Affected versions

v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.0.4
v8.1.0
v8.11.0
v8.11.1
v8.11.2
v8.12.0
v8.12.1
v8.12.2
v8.12.3
v8.13.0
v8.14.0
v8.15.0
v8.16.0
v8.17.0
v8.17.1
v8.17.2
v8.19.0
v8.2.0
v8.20.0
v8.20.1
v8.21.0
v8.22.0
v8.22.1
v8.23.0
v8.23.1
v8.24.0
v8.25.0
v8.26.0
v8.26.1
v8.27.0
v8.28.0
v8.28.1
v8.29.0
v8.3.0
v8.30.0
v8.30.1
v8.31.0
v8.32.0
v8.32.1
v8.33.0
v8.35.0
v8.35.1
v8.36.0
v8.38.0
v8.4.0
v8.40.0
v8.41.0
v8.42.0
v8.42.1
v8.43.0
v8.44.0
v8.45.0
v8.45.1
v8.46.0
v8.47.0
v8.48.0
v8.48.1
v8.48.2
v8.49.0
v8.49.1
v8.49.2
v8.5.0
v8.50.0
v8.51.0
v8.52.0
v8.53.0
v8.53.1
v8.54.0
v8.55.0
v8.56.0
v8.57.0
v8.58.0
v8.59.0
v8.6.0
v8.60.0
v8.61.0
v8.62.0
v8.63.0
v8.64.0
v8.65.0
v8.66.0
v8.67.0
v8.68.0
v8.7.0
v8.7.1
v8.70.0
v8.70.1
v8.70.2
v8.71.0
v8.72.0
v8.73.0
v8.73.1
v8.73.2
v8.74.0
v8.75.0
v8.76.2
v8.77.0
v8.77.1
v8.78.0
v8.8.0
v8.81.0
v8.82.0
v8.83.0
v8.83.1
v8.83.10
v8.83.11
v8.83.12
v8.83.13
v8.83.14
v8.83.16
v8.83.17
v8.83.18
v8.83.19
v8.83.2
v8.83.20
v8.83.3
v8.83.4
v8.83.5
v8.83.7
v8.83.8
v8.83.9
v8.9.0
v9.*
v9.0.0
v9.0.1
v9.0.2
v9.1.0
v9.10.0
v9.10.1
v9.11.0
v9.12.0
v9.12.1
v9.12.2
v9.13.0
v9.14.0
v9.14.1
v9.15.0
v9.16.0
v9.17.0
v9.18.0
v9.19.0
v9.2.0
v9.20.0
v9.21.0
v9.21.1
v9.21.2
v9.21.3
v9.21.4
v9.21.5
v9.21.6
v9.22.0
v9.22.1
v9.23.0
v9.24.0
v9.25.0
v9.25.1
v9.26.0
v9.26.1
v9.27.0
v9.28.0
v9.29.0
v9.3.0
v9.3.1
v9.30.0
v9.30.1
v9.31.0
v9.4.0
v9.4.1
v9.5.0
v9.5.1
v9.6.0
v9.7.0
v9.8.0
v9.8.1
v9.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-40482.json"