laravel/framework is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
15
Low Risk
Affected versions of this package are vulnerable to information disclosure due to improper exception handling when handling SSL/TLS certificate validation fails. Instead of gracefully wrapping low-level Guzzle exceptions into Laravel's standardized ConnectionException, the package leaks raw error details through logs, API responses, or debug pages. Attackers can exploit this vulnerability by inducing SSL failures to harvest sensitive system information, including server file paths from certificate references, middleware configurations from stack traces, and environment details from verbose errors.
You are affected if you are using a version that falls within the vulnerable range.
laravel/framework is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 12.0.0 - 12.17.0.
Upgrade the laravel/framework library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant