CVE-2022-48366
Login timing attack in ezsystems/ezpublish-kernel
3.7
LOW
CVSS 3.1
EPSS 0.46%
描述
Ibexa DXP is using random execution time to hinder timing attacks against user accounts, a method of discovering whether a given account exists in a system without knowing its password, thus affecting privacy. This implementation was found to not be good enough in some situations. The fix replaces this with constant time functionality, configured in the new security.yml parameter 'ibexa.security.authentication.constant_auth_time'. It will log a warning if the constant time is exceeded. If this happens the setting should be increased.
如何修補 CVE-2022-48366
要修補 CVE-2022-48366,請將受影響套件升級到下列已修補版本。
- —升級至 1.3.19 或更新版本
- —升級至 1.3.19 或更新版本
- —升級至 7.5.29 或更新版本
- —升級至 7.5.29 或更新版本
CVE-2022-48366 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- >= 1.3.0, < 1.3.19
- >= 1.3.0, < 1.3.19
- >= 7.5.0, < 7.5.29
- >= 7.5.0, < 7.5.29
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |