Illuminate Auth vulnerabilities
2 known vulnerabilities affecting illuminate/auth.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2017-14775MEDIUM≥ 0, < 5.5.102022-05-17
CVE-2017-14775 [MEDIUM] CWE-200 Laravel Sensitive Data Exposure
Laravel Sensitive Data Exposure
Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.
ghsaosv
CVE-2017-9303MEDIUM≥ 5.3.0, ≤ 5.3.31≥ 5.4.0, < 5.4.222022-05-17
CVE-2017-9303 [MEDIUM] CWE-20 Laravel does not properly constrain the host portion of a password-reset URL
Laravel does not properly constrain the host portion of a password-reset URL
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.
ghsaosv