GHSA-424x-cxvh-wq9p
Mautic allows user name enumeration due to response time difference on password reset form
Quick fix
GHSA-424x-cxvh-wq9p — mautic/core: upgrade to the fixed version with the command below.
composer require mautic/core:^4.4.16Details
### Summary
This advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames.
User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack.
### Mitigation Please update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.
### Workarounds None
If you have any questions or comments about this advisory: Email us at security@mautic.org
Are you affected?
Enter the version of the package you're using.
Affected packages
5.0.0-alphaFixed in: 5.2.6composer require mautic/core:^5.2.66.0.0-alphaFixed in: 6.0.2composer require mautic/core:^6.0.2