{"id":"CVE-2022-48366","details":"An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.","aliases":["GHSA-66m4-gc8h-hpjx"],"modified":"2026-08-12T03:51:10.088628922Z","published":"2023-03-12T00:00:00Z","related":["GHSA-342c-vcff-2ff2","GHSA-xfqg-p48g-hh94"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48366.json","cna_assigner":"mitre"},"references":[{"type":"ADVISORY","url":"https://developers.ibexa.co/security-advisories/ibexa-sa-2022-006-vulnerabilities-in-page-builder-login-and-commerce"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/48xxx/CVE-2022-48366.json"},{"type":"ADVISORY","url":"https://github.com/ezsystems/ezplatform-kernel/security/advisories/GHSA-342c-vcff-2ff2"},{"type":"ADVISORY","url":"https://github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-xfqg-p48g-hh94"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-48366"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ezsystems/ezcommerce","events":[{"introduced":"14186b550123331f59ab9b85032dd96cde8ac9c8"},{"fixed":"8a174a1d3dc4710b437f775ec1f4b021fe7b8624"}],"database_specific":{"extracted_events":[{"introduced":"2.5.0"},{"fixed":"2.5.13"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:ibexa:commerce:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/ezsystems/ezplatform","events":[{"introduced":"0"},{"fixed":"645791e9fdbf7013c38139ec2f8cd3506fb22127"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:ibexa:ez_platform:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.5.30"}]}},{"type":"GIT","repo":"https://github.com/ezsystems/ezplatform-kernel","events":[{"introduced":"0"},{"fixed":"6d7029c0821d17850000d90cc7309875339abd36"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"1.3.19"}]}},{"type":"GIT","repo":"https://github.com/ezsystems/jmspaymentcorebundle","events":[{"introduced":"5a316496d0864d30141b2a168c8c868cd421c5a4"},{"fixed":"0321be452b53c9981047e5259c0e7bc9fd73d28d"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"fixed":"3.0.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:ibexa:jmspaymentcorebundle:*:*:*:*:*:*:*:*"}},{"type":"GIT","repo":"https://github.com/ibexa/commerce","events":[{"introduced":"186cfa6d82e3564efca9b7686e00225cfe4430a1"},{"fixed":"9038d2e14f408255c60a1daba6c53408adccbd01"},{"introduced":"d0594cf367d09d1f0c3ad38fd1eb100f160570ee"},{"fixed":"feae30c4f74ef67c8e3e28d52fe2b0642d15c566"},{"introduced":"3ea957e34737af074b80b7ba3fb400b7d7a59550"},{"fixed":"7a326018cdbb49d2fc427e062743e4cb75cc6406"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:ibexa:commerce:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.3.0"},{"fixed":"3.3.18"},{"introduced":"4.0.0"},{"fixed":"4.0.7"},{"introduced":"4.1.0"},{"fixed":"4.1.4"}]}}],"versions":["v2.5.0","v1.5.1-rc1","v1.5.0","v1.5.0-rc2","v1.5.0-rc1","v1.5.0-beta2","v1.5.0-beta1","v1.4.0","v1.4.0-rc1","v1.4.0-beta1","v1.3.0","v1.3.0-rc2","v1.3.0-beta1","v0.5.0","3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48366.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}