PT-2022-23838 · Plextrac · Plextrac

Vishal Tomar

·

Published

2022-09-08

·

Updated

2023-08-08

·

CVE-2022-37146

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PlexTrac versions prior to 1.28.0
Description The issue allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. An unauthenticated remote attacker can enumerate valid users by measuring the response time of login attempts, as valid, unlocked users take significantly longer to process than invalid users. However, the lockout policy implemented in version 1.17.0 prevents distinguishing between valid, locked user accounts and non-existent user accounts.
Recommendations For versions prior to 1.28.0, update to version 1.28.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the login functionality to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-37146

Affected Products

Plextrac