VDB
Sign up
MEDIUM4.3

GHSA-wmwf-49vv-p3mr

Sulu Observable Response Discrepancy on Admin Login

Quick fix

GHSA-wmwf-49vv-p3mr — sulu/sulu: upgrade to the fixed version with the command below.

composer require sulu/sulu:^2.5.10

Details

### Impact

It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist.

Impacted by this issue are Sulu installation >= 2.5.0 and <2.5.10 using the newer Symfony Security System which is default since Symfony 6.0 but can be enabled in Symfony 5.4. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue.

### Patches

The problem has been patched in version 2.5.10.

### Workarounds

Create a custom AuthenticationFailureHandler which does not return the `$exception->getMessage();` instead the `$exception->getMessageKey();`

### References

Currently no references.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sulu/sulu
Introduced in: 2.5.0Fixed in: 2.5.10
Fixcomposer require sulu/sulu:^2.5.10

References