Skip to content

[FIXED] User base checking vulnerability

Low
azukaar published GHSA-5843-2p4f-57fh Jan 20, 2025

Package

Cosmos-Cloud

Affected versions

< 0.17.7

Patched versions

0.17.7

Description

Impact

By monitoring the error code returned in the login, it is possible to figure out whether a user exist or not in the database

image

Impact is low, as rate-limiting prevent any scanning attempt, so you need to know in advance what you are looking for (and the account name "admin" is forbidden anyway).

Patches

Patched in 0.17.7

Credits

found by "Hannes Michel at Basalt IT-security team"

Severity

Low

CVE ID

CVE-2025-23214

Weaknesses

No CWEs

Credits