{"id":"GHSA-7m2v-x7rg-5hm5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7m2v-x7rg-5hm5","summary":"silverstripe/framework vulnerable to user enumeration via timing attack on login and password reset forms","details":"User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.","published":"2024-05-27T21:45:27Z","modified":"2024-12-02T05:47:34.644237Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.5.5"},{"ecosystem":"Packagist","name":"silverstripe/framework","fixedVersion":"3.6.2"}],"fix":{"url":"https://github.com/silverstripe/silverstripe-framework/commit/f0262a8fd9ab5fb51b178ace3c3487351217f5a0","label":"silverstripe/silverstripe-framework@f0262a8"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/f0262a8fd9ab5fb51b178ace3c3487351217f5a0"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-005-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2017-005"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:47:34.644237Z"}}