PT-2023-9659 · Mendix · Mendix Runtime

Julián Menéndez

+1

·

Published

2023-11-21

·

Updated

2025-01-14

·

CVE-2023-49069

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mendix Runtime V10 versions prior to V10.17.0 Mendix Runtime V10.12 versions prior to V10.12.11 Mendix Runtime V10.6 versions prior to V10.6.19 Mendix Runtime V8 versions prior to V8.18.33 Mendix Runtime V9 versions prior to V9.24.31
Description A vulnerability has been identified in the basic authentication mechanism of Mendix Runtime, which contains an observable response discrepancy when validating usernames. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames, potentially leading to unauthorized access to protected information.
Recommendations For Mendix Runtime V10 versions prior to V10.17.0, update to version V10.17.0 or later to resolve the issue. For Mendix Runtime V10.12 versions prior to V10.12.11, update to version V10.12.11 or later to resolve the issue. For Mendix Runtime V10.6 versions prior to V10.6.19, update to version V10.6.19 or later to resolve the issue. For Mendix Runtime V8 versions prior to V8.18.33, update to version V8.18.33 or later to resolve the issue. For Mendix Runtime V9 versions prior to V9.24.31, update to version V9.24.31 or later to resolve the issue. As a temporary workaround, consider disabling the basic authentication mechanism until a patch is available. Restrict access to the application to minimize the risk of exploitation. Avoid using the basic authentication mechanism in the affected API endpoints until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-09383
CVE-2023-49069

Affected Products

Mendix Runtime