Intel

AIKIDO-2024-10385

laravel/reverb is vulnerable to Weak Authentication

Weak AuthenticationCVE-2024-50347 Published Oct 29, 2024

80

High Risk

This Affects:

phplaravel/reverb
1.0.0 - 1.3.1
Fixed in 1.4.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to weak authentication because not all API endpoints properly utilize the verifySignature method. As a result, certain endpoints may accept unauthorized requests, potentially allowing attackers to bypass authentication and gain access to sensitive resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

laravel/reverb is vulnerable to Weak Authentication in versions 1.0.0 - 1.3.1.

How to fix this

Upgrade the laravel/reverb library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform