{"id":"GHSA-rc8x-jrrc-frfv","summary":"Laravel does not properly constrain the host portion of a password-reset URL","details":"Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.","aliases":["CVE-2017-9303"],"modified":"2024-04-25T23:11:41.248974Z","published":"2022-05-17T02:42:21Z","database_specific":{"github_reviewed_at":"2024-04-25T22:55:13Z","nvd_published_at":"2017-05-29T22:29:00Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9303"},{"type":"WEB","url":"https://github.com/laravel/framework/commit/cef10551820530632a86fa6f1306fee95c5cac43"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/illuminate/auth/CVE-2017-9303.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/laravel/framework/CVE-2017-9303.yaml"},{"type":"WEB","url":"https://laravel-news.com/laravel-5-4-22-is-now-released-and-includes-a-security-fix"},{"type":"WEB","url":"https://laravel.com/docs/5.4/releases#laravel-5.4.22"},{"type":"WEB","url":"https://web.archive.org/web/20171021180417/http://www.securityfocus.com/bid/98776"},{"type":"WEB","url":"http://www.securityfocus.com/bid/98776"}],"affected":[{"package":{"name":"laravel/laravel","ecosystem":"Packagist","purl":"pkg:composer/laravel/laravel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.22"}]}],"versions":["v5.4.0","v5.4.15","v5.4.16","v5.4.19","v5.4.21","v5.4.3","v5.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc8x-jrrc-frfv/GHSA-rc8x-jrrc-frfv.json"}},{"package":{"name":"illuminate/auth","ecosystem":"Packagist","purl":"pkg:composer/illuminate/auth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"last_affected":"5.3.31"}]}],"versions":["v5.3.0","v5.3.16","v5.3.23","v5.3.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc8x-jrrc-frfv/GHSA-rc8x-jrrc-frfv.json"}},{"package":{"name":"illuminate/auth","ecosystem":"Packagist","purl":"pkg:composer/illuminate/auth"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.22"}]}],"versions":["v5.4.0","v5.4.13","v5.4.17","v5.4.19","v5.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc8x-jrrc-frfv/GHSA-rc8x-jrrc-frfv.json"}},{"package":{"name":"laravel/framework","ecosystem":"Packagist","purl":"pkg:composer/laravel/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.3.0"},{"last_affected":"5.3.31"}]}],"versions":["v5.3.0","v5.3.1","v5.3.10","v5.3.11","v5.3.12","v5.3.13","v5.3.14","v5.3.15","v5.3.16","v5.3.17","v5.3.18","v5.3.19","v5.3.2","v5.3.20","v5.3.21","v5.3.22","v5.3.23","v5.3.24","v5.3.25","v5.3.26","v5.3.27","v5.3.28","v5.3.29","v5.3.3","v5.3.30","v5.3.31","v5.3.4","v5.3.5","v5.3.6","v5.3.7","v5.3.8","v5.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc8x-jrrc-frfv/GHSA-rc8x-jrrc-frfv.json"}},{"package":{"name":"laravel/framework","ecosystem":"Packagist","purl":"pkg:composer/laravel/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.0"},{"fixed":"5.4.22"}]}],"versions":["v5.4.0","v5.4.1","v5.4.10","v5.4.11","v5.4.12","v5.4.13","v5.4.14","v5.4.15","v5.4.16","v5.4.17","v5.4.18","v5.4.19","v5.4.2","v5.4.20","v5.4.21","v5.4.3","v5.4.4","v5.4.5","v5.4.6","v5.4.7","v5.4.8","v5.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rc8x-jrrc-frfv/GHSA-rc8x-jrrc-frfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}