{"id":"GHSA-2frx-j9hj-6c65","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2frx-j9hj-6c65","summary":"User enumeration in authentication mechanisms","details":"Description\n-----------\n\nThe ability to enumerate users was possible without relevant permissions due to different exception messages depending on whether the user existed or not. \n\nResolution\n----------\n\nWe now ensure that a generic message is returned whether the user exists or not if the password is invalid or if the user does not exist.\n\nThe patch for this issue is available [here](https://github.com/lexik/LexikJWTAuthenticationBundle/commit/a175d6dab968d93e96a3e4f80c495435f71d5eb7) for branch 2.10.x and 2.x.\n\nCredits\n-------\n\nI would like to thank James Isaac and Mathias Brodala for reporting the issue and Robin Chalas for fixing the issue.","published":"2021-05-17T20:52:21Z","modified":"2024-12-02T05:54:53.242476Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"lexik/jwt-authentication-bundle","fixedVersion":"2.10.7"},{"ecosystem":"Packagist","name":"lexik/jwt-authentication-bundle","fixedVersion":"2.11.3"}],"fix":{"url":"https://github.com/lexik/LexikJWTAuthenticationBundle/commit/a175d6dab968d93e96a3e4f80c495435f71d5eb7","label":"lexik/LexikJWTAuthenticationBundle@a175d6d"},"references":[{"type":"WEB","url":"https://github.com/lexik/LexikJWTAuthenticationBundle/security/advisories/GHSA-2frx-j9hj-6c65"},{"type":"WEB","url":"https://github.com/lexik/LexikJWTAuthenticationBundle/commit/a175d6dab968d93e96a3e4f80c495435f71d5eb7"},{"type":"WEB","url":"https://github.com/lexik/LexikJWTAuthenticationBundle"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:54:53.242476Z"}}