CyberRota Analysis
AI-GeneratedThe alexpechkarev/google-maps Laravel package is vulnerable due to its default configuration, which disables TLS certificate verification, allowing on-path attackers to intercept requests to Google Maps services. This flaw can lead to the theft of API keys and manipulation of service responses, posing significant risks to applications relying on this package. Developers and organizations using this Laravel package should prioritize remediation to safeguard their applications against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.