Описание
Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.2.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. This issue has been patched in version 2.2.0.
Уязвимые конфигурации
Конфигурация 1Версия до 2.2.0 (исключая)
cpe:2.3:a:sync-in:sync-in_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00333
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-208
Связанные уязвимости
EPSS
Процентиль: 26%
0.00333
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-208