CVE-2022-25838: High severity laravel fortify vulnerability
Published Feb 23, 2022
·Updated
Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.
Other sources
Multi-Factor Authentication issue in Laravel Fortify
Affected Software
3 affected componentsFixes available
composer/laravel/fortify<1.11.1
composer/laravel/fortify<1.11.1
1.11.1
Laravel Fortify<1.11.1
Event History
Feb 23, 2022
Advisory Published
04:04 PM
Feb 24, 2022
CVE Published
via MITRE·02:43 AM
Data Sourced
via MITRE·02:43 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-25838?
CVE-2022-25838 has a medium severity rating due to its potential impact on multi-factor authentication security.
2
How do I fix CVE-2022-25838?
To fix CVE-2022-25838, update Laravel Fortify to version 1.11.1 or later.
3
What is the main issue with CVE-2022-25838?
The main issue with CVE-2022-25838 is that it allows reuse of authentication codes within a short time frame, undermining the security of TOTP.
4
Which versions of Laravel Fortify are affected by CVE-2022-25838?
CVE-2022-25838 affects Laravel Fortify versions prior to 1.11.1.
5
Can CVE-2022-25838 be exploited remotely?
Yes, CVE-2022-25838 can potentially be exploited remotely, affecting users' security during multi-factor authentication processes.