Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jvfr-jf2p-rc53

Опубликовано: 21 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

EPSS

Процентиль: 26%
0.0009
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208

Связанные уязвимости

CVSS3: 5.3
nvd
11 месяцев назад

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

EPSS

Процентиль: 26%
0.0009
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-208