← back
CVE-2024-29291

CVE-2024-29291

EPSS 1.3%CWE-200
Vexday Risk Score
23Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS EPSS 1.3%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
16 Apr 2024Published on NVD
21 Apr 2024Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/logs/laravel.log. NOTE: this is disputed by multiple third parties because the owner of a Laravel Framework installation can choose to have debugging logs, but needs to set the access control appropriately for the type of data that may be logged.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →