High severityNVD Advisory· Published Feb 24, 2022· Updated Aug 3, 2024
CVE-2022-25838
CVE-2022-25838
Description
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
laravel/fortifyPackagist | < 1.11.1 | 1.11.1 |
Affected products
2- Laravel/Fortifydescription
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-6w4v-qr4m-97ggghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25838ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/laravel/fortify/CVE-2022-25838.yamlghsaWEB
- github.com/laravel/fortify/issues/201ghsaWEB
- github.com/laravel/fortify/issues/201ghsax_refsource_MISCWEB
- github.com/laravel/fortify/pull/357ghsaWEB
- github.com/laravel/fortify/pull/358ghsaWEB
News mentions
0No linked articles in our index yet.