Laravel 'Hash::make()' Function Password Truncation Security Weakness
BID:69849
Info
Laravel 'Hash::make()' Function Password Truncation Security Weakness
| Bugtraq ID: | 69849 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2014 12:00AM |
| Updated: | Sep 16 2014 12:00AM |
| Credit: | Pichaya Morimoto |
| Vulnerable: |
Laravel Laravel 2.1 |
| Not Vulnerable: | |
Discussion
Laravel 'Hash::make()' Function Password Truncation Security Weakness
Laravel is prone to a security weakness due to pseudo password hash collision.
Attackers can exploit this issue to bypass intended security restrictions. This may aid in further attacks.
Laravel is prone to a security weakness due to pseudo password hash collision.
Attackers can exploit this issue to bypass intended security restrictions. This may aid in further attacks.
Exploit / POC
Laravel 'Hash::make()' Function Password Truncation Security Weakness
The following proof-of-concept is available:
The following proof-of-concept is available: