Логотип exploitDog
bind:CVE-2025-30344
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30344

Количество 2

Количество 2

nvd логотип

CVE-2025-30344

11 месяцев назад

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jvfr-jf2p-rc53

11 месяцев назад

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30344

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

CVSS3: 5.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-jvfr-jf2p-rc53

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

CVSS3: 5.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу