Vulnerability record · CVE-2022-24784 · published 25 March 2022
CVE-2022-24784: Statamic information exposure vulnerability
Statamic · Statamic
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.
Description
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/statamic/cms/issues/5604 | Issue TrackingPatchThird Party Advisory |
| https://github.com/statamic/cms/pull/5568 | PatchThird Party Advisory |
| https://github.com/statamic/cms/security/advisories/GHSA-qcgx-7p5f-hxvr | Third Party Advisory |
| https://github.com/statamic/cms/issues/5604 | Issue TrackingPatchThird Party Advisory |
| https://github.com/statamic/cms/pull/5568 | PatchThird Party Advisory |
| https://github.com/statamic/cms/security/advisories/GHSA-qcgx-7p5f-hxvr | Third Party Advisory |
Track CVE-2022-24784 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-24784), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.