PT-2022-28126 · Ibexa · Ibexa Dxp+1

Christoph Rottermanner

+1

·

Published

2022-06-02

·

Updated

2025-03-04

·

CVE-2022-48366

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions eZ Platform Ibexa Kernel versions prior to 1.3.19
Description The issue allows determining account existence via a timing attack, affecting privacy. Ibexa DXP's implementation of random execution time to hinder timing attacks was found to be insufficient in some situations. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the use of timing attacks against user accounts, which can discover whether a given account exists in a system without knowing its password.
Recommendations For versions prior to 1.3.19, update to version 1.3.19 or later, which replaces the random execution time with constant time functionality, configured in the new security.yml parameter ibexa.security.authentication.constant auth time. As a temporary workaround, consider increasing the ibexa.security.authentication.constant auth time setting if a warning is logged due to the constant time being exceeded.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-48366
GHSA-342C-VCFF-2FF2
GHSA-66M4-GC8H-HPJX
GHSA-XFQG-P48G-HH94

Affected Products

Ibexa Dxp
Ez Platform Ibexa Kernel