Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmwf-49vv-p3mr

Опубликовано: 03 авг. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Sulu Observable Response Discrepancy on Admin Login

Impact

It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist.

Impacted by this issue are Sulu installation >= 2.5.0 and <2.5.10 using the newer Symfony Security System which is default since Symfony 6.0 but can be enabled in Symfony 5.4. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue.

Patches

The problem has been patched in version 2.5.10.

Workarounds

Create a custom AuthenticationFailureHandler which does not return the $exception->getMessage(); instead the $exception->getMessageKey();

References

Currently no references.

Пакеты

Наименование

sulu/sulu

composer
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.10

2.5.10

EPSS

Процентиль: 58%
0.00362
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. The vulnerability has been patched in version 2.5.10.

EPSS

Процентиль: 58%
0.00362
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-204