VDB
Sign up
MEDIUM5.3

GHSA-424x-cxvh-wq9p

Mautic allows user name enumeration due to response time difference on password reset form

Quick fix

GHSA-424x-cxvh-wq9p — mautic/core: upgrade to the fixed version with the command below.

composer require mautic/core:^4.4.16

Details

### Summary

This advisory addresses a security vulnerability in Mautic related to the "Forget your password" functionality. This vulnerability could be exploited by unauthenticated users to enumerate valid usernames.

User Enumeration via Timing Attack: A user enumeration vulnerability exists in the "Forget your password" functionality. Differences in response times for existing and non-existing users, combined with a lack of request limiting, allow an attacker to determine the existence of usernames through a timing-based attack.

### Mitigation Please update to a version that addresses this timing vulnerability, where password reset responses are normalized to respond at the same time regardless of user existence.

### Workarounds None

If you have any questions or comments about this advisory: Email us at security@mautic.org

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/mautic/core
Introduced in: 1.0.0Fixed in: 4.4.16
Fixcomposer require mautic/core:^4.4.16
Packagist/mautic/core
Introduced in: 5.0.0-alphaFixed in: 5.2.6
Fixcomposer require mautic/core:^5.2.6
Packagist/mautic/core
Introduced in: 6.0.0-alphaFixed in: 6.0.2
Fixcomposer require mautic/core:^6.0.2

References