Skip to content

Observable Timing Discrepancy in Login Form

Moderate
Abraxas-Bot published GHSA-865c-qrvq-m655 Sep 9, 2022

Package

VOTING IAM (Abraxas Apps Platform)

Affected versions

< v1.8.4

Patched versions

v1.8.4

Description

Short Description

User enumeration based on response times

Reporting Date

  1. August 2022

Details  

Based on the duration of the response time for a login attempt, it was possible to identify whether the specified user was in the system or not.

This determination can be used for further attacks against existing users. Executing a login attempt for a non-existing user only takes a few milliseconds while an existing user needs significant more time. The backend does not ensure similar delays for different scenarios.  

Impact

Low

References

❤ Thanks to

Simon Reinhart for detection and reporting of the vulnerability.

Severity

Moderate
4.3
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

No known CVE

Weaknesses