Skip to content

Conversation

@valorin
Copy link
Contributor

@valorin valorin commented May 11, 2025

Backporting the fixes from #55701 into the 11.x branch, given it's a security-related fix.

@GrahamCampbell
Copy link
Collaborator

This was not considered a security fix at the time, just an enhancement. I don't think we need to do this. If we do, then we'd need to raise a CVE for the original change.

@valorin
Copy link
Contributor Author

valorin commented May 11, 2025

The Timebox was originally added as part of the attempt at fixing GHSA-5qxg-5vwh-7j5j (CVE-2022-40482), so as far as I am concerned, it should be backported and a CVEs should be issued/updated (not sure if the process is to update the old one or just issue a new one).

@taylorotwell taylorotwell merged commit 776653a into laravel:11.x May 11, 2025
59 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

3 participants