Skip to content

Commit

Permalink
check iv length
Browse files Browse the repository at this point in the history
  • Loading branch information
taylorotwell committed Mar 30, 2018
1 parent c4ad57e commit 28e53f2
Showing 1 changed file with 2 additions and 3 deletions.
5 changes: 2 additions & 3 deletions src/Illuminate/Encryption/Encrypter.php
Original file line number Diff line number Diff line change
Expand Up @@ -206,9 +206,8 @@ protected function getJsonPayload($payload)
*/
protected function validPayload($payload)
{
return is_array($payload) && isset(
$payload['iv'], $payload['value'], $payload['mac']
);
return is_array($payload) && isset($payload['iv'], $payload['value'], $payload['mac']) &&
strlen(base64_decode($payload['iv'], true)) === openssl_cipher_iv_length($this->cipher);
}

/**
Expand Down

0 comments on commit 28e53f2

Please sign in to comment.