Skip to content

IBX-1755: Login timing attack

Critical
glye published GHSA-xfqg-p48g-hh94 May 31, 2022

Package

composer ezsystems/ezpublish-kernel (Composer)

Affected versions

v7.5.*

Patched versions

v7.5.29

Severity

Critical

CVE ID

No known CVE

Weaknesses

Observable Timing Discrepancy

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not. Learn more on MITRE.