gist.github.com
https://gist.github.com/whiteman007/43bd7fa1fa0e47554b33f0cf93066784 CVE-2024-29291
Laravel Laravel Framework Exposure of Sensitive Information to an Unauthorized Actor
Record summary
EIP currently links 1 catalogued exploit to CVE-2024-29291.
Description
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 27, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 25, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Laravel FrameworkBrowse Laravel / Laravel Framework | VulnCheck | Version data not supplied | |
frameworkBrowse laravel / frameworkDefault status: unknown | CVE List | 8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBLaravel Framework 11 - Credential LeakageExploitDB exploitby Huseein AmerNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29291