jayanta/laravel-threat-detection Security Advisories for v1.5.0 (4)
-
Marking a detection as a false positive could create a wider exclusion rule than intended
Affected version: <1.9.0
Reported by:
FriendsOfPHP/security-advisories -
Attacks go unrecorded when a request carries malformed headers or oversized fields
Affected version: <1.9.0
Reported by:
FriendsOfPHP/security-advisories -
Credentials under prefixed or nested names stored in cleartext in the threat log
Affected version: <1.9.0
Reported by:
FriendsOfPHP/security-advisories -
Plaintext credentials written to the threat log and readable by any authenticated user
Affected version: <1.8.0
Reported by:
FriendsOfPHP/security-advisories