{"id":"GHSA-7m2v-x7rg-5hm5","summary":"silverstripe/framework vulnerable to user enumeration via timing attack on login and password reset forms","details":"User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.","modified":"2024-12-02T05:47:34.644237Z","published":"2024-05-27T21:45:27Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-27T21:45:27Z"},"references":[{"type":"WEB","url":"https://github.com/silverstripe/silverstripe-framework/commit/f0262a8fd9ab5fb51b178ace3c3487351217f5a0"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-005-1.yaml"},{"type":"PACKAGE","url":"https://github.com/silverstripe/silverstripe-framework"},{"type":"WEB","url":"https://www.silverstripe.org/download/security-releases/ss-2017-005"}],"affected":[{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0-rc1"},{"fixed":"3.5.5"}]}],"versions":["3.5.0","3.5.0-rc1","3.5.0-rc2","3.5.0-rc3","3.5.1","3.5.1-rc1","3.5.1-rc2","3.5.2","3.5.2-rc1","3.5.3","3.5.3-rc1","3.5.4","3.5.4-rc1","3.5.5-beta1","3.5.5-beta2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json"}},{"package":{"name":"silverstripe/framework","ecosystem":"Packagist","purl":"pkg:composer/silverstripe/framework"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.6.0-rc1"},{"fixed":"3.6.2"}]}],"versions":["3.6.0","3.6.0-rc1","3.6.1","3.6.1-alpha2","3.6.2-beta1","3.6.2-beta2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-7m2v-x7rg-5hm5/GHSA-7m2v-x7rg-5hm5.json"}}],"schema_version":"1.9.0"}