PT-2021-24369 · Unknown · Lexikjwtauthenticationbundle

Published

2021-05-17

·

Updated

2021-05-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: LexikJWTAuthenticationBundle versions 2.10.x and 2.x
Description: The issue allowed user enumeration without proper permissions due to different exception messages depending on whether the user existed or not. This could potentially reveal sensitive information about the system's users.
Recommendations: For LexikJWTAuthenticationBundle versions 2.10.x and 2.x, apply the patch available for these branches to resolve the issue.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-2FRX-J9HJ-6C65

Affected Products

Lexikjwtauthenticationbundle