Vulnerability Details CVE-2022-40482
The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This is caused by the early return inside the hasValidCredentials method in the Illuminate\Auth\SessionGuard class when a user is found to not exist.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-40482
-
cpe:2.3:a:laravel:framework:8.0.0
-
cpe:2.3:a:laravel:framework:8.0.1
-
cpe:2.3:a:laravel:framework:8.0.2
-
cpe:2.3:a:laravel:framework:8.0.3
-
cpe:2.3:a:laravel:framework:8.0.4
-
cpe:2.3:a:laravel:framework:8.1.0
-
cpe:2.3:a:laravel:framework:8.10.0
-
cpe:2.3:a:laravel:framework:8.11.0
-
cpe:2.3:a:laravel:framework:8.11.1
-
cpe:2.3:a:laravel:framework:8.11.2
-
cpe:2.3:a:laravel:framework:8.12.0
-
cpe:2.3:a:laravel:framework:8.12.1
-
cpe:2.3:a:laravel:framework:8.12.2
-
cpe:2.3:a:laravel:framework:8.12.3
-
cpe:2.3:a:laravel:framework:8.13.0
-
cpe:2.3:a:laravel:framework:8.14.0
-
cpe:2.3:a:laravel:framework:8.15.0
-
cpe:2.3:a:laravel:framework:8.16.0
-
cpe:2.3:a:laravel:framework:8.16.1
-
cpe:2.3:a:laravel:framework:8.17.0
-
cpe:2.3:a:laravel:framework:8.17.1
-
cpe:2.3:a:laravel:framework:8.17.2
-
cpe:2.3:a:laravel:framework:8.18.0
-
cpe:2.3:a:laravel:framework:8.18.1
-
cpe:2.3:a:laravel:framework:8.19.0
-
cpe:2.3:a:laravel:framework:8.2.0
-
cpe:2.3:a:laravel:framework:8.20.0
-
cpe:2.3:a:laravel:framework:8.20.1
-
cpe:2.3:a:laravel:framework:8.21.0
-
cpe:2.3:a:laravel:framework:8.22.0
-
cpe:2.3:a:laravel:framework:8.22.1
-
cpe:2.3:a:laravel:framework:8.23.0
-
cpe:2.3:a:laravel:framework:8.23.1
-
cpe:2.3:a:laravel:framework:8.24.0
-
cpe:2.3:a:laravel:framework:8.25.0
-
cpe:2.3:a:laravel:framework:8.26.0
-
cpe:2.3:a:laravel:framework:8.26.1
-
cpe:2.3:a:laravel:framework:8.27.0
-
cpe:2.3:a:laravel:framework:8.28.0
-
cpe:2.3:a:laravel:framework:8.28.1
-
cpe:2.3:a:laravel:framework:8.29.0
-
cpe:2.3:a:laravel:framework:8.3.0
-
cpe:2.3:a:laravel:framework:8.30.0
-
cpe:2.3:a:laravel:framework:8.30.1
-
cpe:2.3:a:laravel:framework:8.31.0
-
cpe:2.3:a:laravel:framework:8.32.0
-
cpe:2.3:a:laravel:framework:8.32.1
-
cpe:2.3:a:laravel:framework:8.33.0
-
cpe:2.3:a:laravel:framework:8.33.1
-
cpe:2.3:a:laravel:framework:8.34.0
-
cpe:2.3:a:laravel:framework:8.35.0
-
cpe:2.3:a:laravel:framework:8.35.1
-
cpe:2.3:a:laravel:framework:8.36.0
-
cpe:2.3:a:laravel:framework:8.36.1
-
cpe:2.3:a:laravel:framework:8.36.2
-
cpe:2.3:a:laravel:framework:8.37.0
-
cpe:2.3:a:laravel:framework:8.38.0
-
cpe:2.3:a:laravel:framework:8.39.0
-
cpe:2.3:a:laravel:framework:8.4.0
-
cpe:2.3:a:laravel:framework:8.40.0
-
cpe:2.3:a:laravel:framework:8.41.0
-
cpe:2.3:a:laravel:framework:8.42.0
-
cpe:2.3:a:laravel:framework:8.42.1
-
cpe:2.3:a:laravel:framework:8.43.0
-
cpe:2.3:a:laravel:framework:8.44.0
-
cpe:2.3:a:laravel:framework:8.45.0
-
cpe:2.3:a:laravel:framework:8.45.1
-
cpe:2.3:a:laravel:framework:8.46.0
-
cpe:2.3:a:laravel:framework:8.47.0
-
cpe:2.3:a:laravel:framework:8.48.0
-
cpe:2.3:a:laravel:framework:8.48.1
-
cpe:2.3:a:laravel:framework:8.48.2
-
cpe:2.3:a:laravel:framework:8.49.0
-
cpe:2.3:a:laravel:framework:8.49.1
-
cpe:2.3:a:laravel:framework:8.49.2
-
cpe:2.3:a:laravel:framework:8.5.0
-
cpe:2.3:a:laravel:framework:8.50.0
-
cpe:2.3:a:laravel:framework:8.51.0
-
cpe:2.3:a:laravel:framework:8.52.0
-
cpe:2.3:a:laravel:framework:8.53.0
-
cpe:2.3:a:laravel:framework:8.53.1
-
cpe:2.3:a:laravel:framework:8.54.0
-
cpe:2.3:a:laravel:framework:8.55.0
-
cpe:2.3:a:laravel:framework:8.56.0
-
cpe:2.3:a:laravel:framework:8.57.0
-
cpe:2.3:a:laravel:framework:8.58.0
-
cpe:2.3:a:laravel:framework:8.59.0
-
cpe:2.3:a:laravel:framework:8.6.0
-
cpe:2.3:a:laravel:framework:8.60.0
-
cpe:2.3:a:laravel:framework:8.61.0
-
cpe:2.3:a:laravel:framework:8.62.0
-
cpe:2.3:a:laravel:framework:8.63.0
-
cpe:2.3:a:laravel:framework:8.64.0
-
cpe:2.3:a:laravel:framework:8.65.0
-
cpe:2.3:a:laravel:framework:8.66.0
-
cpe:2.3:a:laravel:framework:8.67.0
-
cpe:2.3:a:laravel:framework:8.68.0
-
cpe:2.3:a:laravel:framework:8.68.1
-
cpe:2.3:a:laravel:framework:8.69.0
-
cpe:2.3:a:laravel:framework:8.7.0
-
cpe:2.3:a:laravel:framework:8.7.1
-
cpe:2.3:a:laravel:framework:8.70.0
-
cpe:2.3:a:laravel:framework:8.70.1
-
cpe:2.3:a:laravel:framework:8.70.2
-
cpe:2.3:a:laravel:framework:8.71.0
-
cpe:2.3:a:laravel:framework:8.72.0
-
cpe:2.3:a:laravel:framework:8.73.0
-
cpe:2.3:a:laravel:framework:8.73.1
-
cpe:2.3:a:laravel:framework:8.73.2
-
cpe:2.3:a:laravel:framework:8.74.0
-
cpe:2.3:a:laravel:framework:8.75.0
-
cpe:2.3:a:laravel:framework:8.76.0
-
cpe:2.3:a:laravel:framework:8.76.1
-
cpe:2.3:a:laravel:framework:8.76.2
-
cpe:2.3:a:laravel:framework:8.77.0
-
cpe:2.3:a:laravel:framework:8.77.1
-
cpe:2.3:a:laravel:framework:8.78.0
-
cpe:2.3:a:laravel:framework:8.78.1
-
cpe:2.3:a:laravel:framework:8.79.0
-
cpe:2.3:a:laravel:framework:8.8.0
-
cpe:2.3:a:laravel:framework:8.80.0
-
cpe:2.3:a:laravel:framework:8.81.0
-
cpe:2.3:a:laravel:framework:8.82.0
-
cpe:2.3:a:laravel:framework:8.83.0
-
cpe:2.3:a:laravel:framework:8.83.1
-
cpe:2.3:a:laravel:framework:8.83.10
-
cpe:2.3:a:laravel:framework:8.83.11
-
cpe:2.3:a:laravel:framework:8.83.12
-
cpe:2.3:a:laravel:framework:8.83.13
-
cpe:2.3:a:laravel:framework:8.83.14
-
cpe:2.3:a:laravel:framework:8.83.15
-
cpe:2.3:a:laravel:framework:8.83.16
-
cpe:2.3:a:laravel:framework:8.83.17
-
cpe:2.3:a:laravel:framework:8.83.18
-
cpe:2.3:a:laravel:framework:8.83.19
-
cpe:2.3:a:laravel:framework:8.83.2
-
cpe:2.3:a:laravel:framework:8.83.20
-
cpe:2.3:a:laravel:framework:8.83.21
-
cpe:2.3:a:laravel:framework:8.83.22
-
cpe:2.3:a:laravel:framework:8.83.23
-
cpe:2.3:a:laravel:framework:8.83.3
-
cpe:2.3:a:laravel:framework:8.83.4
-
cpe:2.3:a:laravel:framework:8.83.5
-
cpe:2.3:a:laravel:framework:8.83.6
-
cpe:2.3:a:laravel:framework:8.83.7
-
cpe:2.3:a:laravel:framework:8.83.8
-
cpe:2.3:a:laravel:framework:8.83.9
-
cpe:2.3:a:laravel:framework:8.9.0
-
cpe:2.3:a:laravel:framework:9.0.0
-
cpe:2.3:a:laravel:framework:9.0.1
-
cpe:2.3:a:laravel:framework:9.0.2
-
cpe:2.3:a:laravel:framework:9.1.0
-
cpe:2.3:a:laravel:framework:9.10.0
-
cpe:2.3:a:laravel:framework:9.10.1
-
cpe:2.3:a:laravel:framework:9.11.0
-
cpe:2.3:a:laravel:framework:9.12.0
-
cpe:2.3:a:laravel:framework:9.12.1
-
cpe:2.3:a:laravel:framework:9.12.2
-
cpe:2.3:a:laravel:framework:9.13.0
-
cpe:2.3:a:laravel:framework:9.14.0
-
cpe:2.3:a:laravel:framework:9.14.1
-
cpe:2.3:a:laravel:framework:9.15.0
-
cpe:2.3:a:laravel:framework:9.16.0
-
cpe:2.3:a:laravel:framework:9.17.0
-
cpe:2.3:a:laravel:framework:9.18.0
-
cpe:2.3:a:laravel:framework:9.19.0
-
cpe:2.3:a:laravel:framework:9.2.0
-
cpe:2.3:a:laravel:framework:9.20.0
-
cpe:2.3:a:laravel:framework:9.21.0
-
cpe:2.3:a:laravel:framework:9.21.1
-
cpe:2.3:a:laravel:framework:9.21.2
-
cpe:2.3:a:laravel:framework:9.21.3
-
cpe:2.3:a:laravel:framework:9.21.4
-
cpe:2.3:a:laravel:framework:9.21.5
-
cpe:2.3:a:laravel:framework:9.21.6
-
cpe:2.3:a:laravel:framework:9.22.0
-
cpe:2.3:a:laravel:framework:9.22.1
-
cpe:2.3:a:laravel:framework:9.23.0
-
cpe:2.3:a:laravel:framework:9.24.0
-
cpe:2.3:a:laravel:framework:9.25.0
-
cpe:2.3:a:laravel:framework:9.25.1
-
cpe:2.3:a:laravel:framework:9.26.0
-
cpe:2.3:a:laravel:framework:9.26.1
-
cpe:2.3:a:laravel:framework:9.27.0
-
cpe:2.3:a:laravel:framework:9.28.0
-
cpe:2.3:a:laravel:framework:9.29.0
-
cpe:2.3:a:laravel:framework:9.3.0
-
cpe:2.3:a:laravel:framework:9.3.1
-
cpe:2.3:a:laravel:framework:9.30.0
-
cpe:2.3:a:laravel:framework:9.30.1
-
cpe:2.3:a:laravel:framework:9.31.0
-
cpe:2.3:a:laravel:framework:9.4.0
-
cpe:2.3:a:laravel:framework:9.4.1
-
cpe:2.3:a:laravel:framework:9.5.0
-
cpe:2.3:a:laravel:framework:9.5.1
-
cpe:2.3:a:laravel:framework:9.6.0
-
cpe:2.3:a:laravel:framework:9.7.0
-
cpe:2.3:a:laravel:framework:9.8.0
-
cpe:2.3:a:laravel:framework:9.8.1
-
cpe:2.3:a:laravel:framework:9.9.0