PT-2022-23838 · Plextrac · Plextrac
Vishal Tomar
·
Published
2022-09-08
·
Updated
2023-08-08
·
CVE-2022-37146
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PlexTrac versions prior to 1.28.0
Description
The issue allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. An unauthenticated remote attacker can enumerate valid users by measuring the response time of login attempts, as valid, unlocked users take significantly longer to process than invalid users. However, the lockout policy implemented in version 1.17.0 prevents distinguishing between valid, locked user accounts and non-existent user accounts.
Recommendations
For versions prior to 1.28.0, update to version 1.28.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the login functionality to minimize the risk of exploitation.
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plextrac