VDB
Sign up
MEDIUM5.9

GHSA-3ggv-qwcp-j6xg

Mautic Vulnerable to User Enumeration via Response Timing

Quick fix

GHSA-3ggv-qwcp-j6xg — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^4.4.17

Details

### Impact The attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks.

### Patches This vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not.

### Technical Details The vulnerability was caused by different response times when: - A valid username was provided (password hashing occurred) - An invalid username was provided (no password hashing occurred)

The fix introduces a `TimingSafeFormLoginAuthenticator` that performs a dummy password hash verification even for non-existent users, ensuring consistent timing.

### Workarounds No workarounds are available. Users should upgrade to the patched version.

### References - https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/03-Identity_Management_Testing/04-Testing_for_Account_Enumeration_and_Guessable_User_Account - https://github.com/mautic/mautic-security/pull/146

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 4.4.0Fixed in: 4.4.17
Fixcomposer require mautic/core:^4.4.17
Packagist/mautic/core
Introduced in: 5.0.0-alphaFixed in: 5.2.8
Fixcomposer require mautic/core:^5.2.8
Packagist/mautic/core
Introduced in: 6.0.0-alphaFixed in: 6.0.5
Fixcomposer require mautic/core:^6.0.5

References