Skip to content

IBX-1755: Login timing attack

Critical
glye published GHSA-2x4v-g8cx-jxrq May 31, 2022

Package

composer ibexa/core (Composer)

Affected versions

v4.0.*, v4.1.*

Patched versions

v4.0.7, v4.1.4

Severity

Critical

CVE ID

No known CVE

Weaknesses

Observable Timing Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not. Learn more on MITRE.