Skip to content

Observable Timing Discrepancy in Login Process

Low
Abraxas-Bot published GHSA-6g8v-7xjv-w59g Sep 16, 2022

Package

VOTING IAM (Abraxas Apps Platform)

Affected versions

< 2022-09-16

Patched versions

2022-09-16

Description

Short Description

User enumeration based on service times

Reporting Date

  1. August 2022

Details

During the login request, the user receives information from the backend system about the processing time of the request.

This information, recognizable in the HTTP header x-envoy-upstream-service-time can be used to detect whether the login request is valid user in the system.

Impact

Low

References

❤ Thanks to

Simon Reinhart for reporting the vulnerability.

Severity

Low

CVE ID

No known CVE

Weaknesses