VDB
Sign up
LOW

GHSA-6f65-4fv2-wwch

Vendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategy

Quick fix

GHSA-6f65-4fv2-wwch — @vendure/core: upgrade to the fixed version with the command below.

npm install @vendure/core@3.5.3

Details

### Summary The `NativeAuthenticationStrategy.authenticate()` method is vulnerable to a timing attack that allows attackers to enumerate valid usernames (email addresses).

### Details In `packages/core/src/config/auth/native-authentication-strategy.ts`, the authenticate method returns immediately if a user is not found:

```typescript const user = await this.userService.getUserByEmailAddress(ctx, data.username); if (!user) { return false; // Instant return (~1-5ms) } const passwordMatch = await this.verifyUserPassword(ctx, user.id, data.password); // Password check takes ~200-400ms with bcrypt (12 rounds) ```

The significant timing difference (~200-400ms for bcrypt vs ~1-5ms for DB miss) allows attackers to reliably distinguish between existing and non-existing accounts.

### Impact - Attackers can enumerate valid user accounts - Enables targeted brute-force or phishing attacks - Information disclosure (account existence)

### Recommended Fix Perform a dummy bcrypt check when user is not found to ensure consistent response times.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@vendure/core
Introduced in: 0Fixed in: 3.5.3
Fixnpm install @vendure/core@3.5.3

References