CWE-203

Observable Discrepancy

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

751 vulnerabilities with CWE-203
CVE-2024-5690 MEDIUM
Firefox < 127.0 and ESR < 115.12 - Information Disclosure via External Protocol Handler Timing
CVSS 4.3
CVE-2024-37880 HIGH
pq-crystals/kyber < 2024-06-03 - Timing Side-Channel Attack via Secret-Dependent Branch in poly_frommsg
CVSS 7.5
CVE-2024-2408 MEDIUM
PHP >=8.1.0 <8.1.29 - Observable Discrepancy via OpenSSL PKCS1 Padding
CVSS 5.9
CVE-2024-31878 MEDIUM
IBM i 7.2-7.5 - SST User Enumeration
CVSS 5.3
CVE-2024-5124 HIGH
gaizhenbiao/chuanhuchatgpt <20240310 - Info Disclosure
CVSS 7.5
CVE-2024-30171 MEDIUM
Bouncy Castle Java TLS API & JSSE Provider <1.78 - Info Disclosure
CVSS 5.9
CVE-2024-27839 LOW
iPadOS < 17.5 - Unprotected User Location Exposure
CVSS 3.3
CVE-2024-30176 MEDIUM
Logpoint SIEM < 7.4.0 - Username Enumeration via Shared Widget URLs
CVSS 5.3
CVE-2024-30257 LOW
1Panel < 1.10.3-lts - Timing Attack via Password Verification
CVSS 3.9
CVE-2024-26221 HIGH
Windows Server RCE (2016 < 10.0.14393.6897, 2019 < 10.0.17763.5696, 2022 < 10.0.20348.2402, 23H2 < 10.0.25398.830)
CVSS 7.2
CVE-2024-2464 MEDIUM
CDeX < 5.71 - User Enumeration via Password Recovery Message Discrepancy
CVSS 6.3
CVE-2024-28868 LOW
Umbraco CMS 10.0.0-10.8.4 - User Enumeration via Native Login Screen
CVSS 3.7
CVE-2024-25651 MEDIUM
Delinea Secret Server 11.4 - User Enumeration via OAuth2 Token Endpoint
CVSS 5.3
CVE-2024-24766 MEDIUM
CasaOS-UserService 0.4.4.3-0.4.6 - Username Enumeration via Login Error Messages
CVSS 6.2
CVE-2024-0436 MEDIUM
AnythingLLM < 1.0.0 - Timing Attack via Password Comparison
CVSS 5.9
CVE-2024-26268 MEDIUM
Liferay Portal 7.2.0-7.4.3.26 and DXP < 7.4 Update 27 - User Enumeration via Response Time Discrepancy
CVSS 5.3
CVE-2024-25714 CRITICAL
Rhonabwy < 1.1.13 - Timing Side-Channel Attack via HMAC Signature Verification
CVSS 9.8
CVE-2024-25191 CRITICAL
php-jwt 1.0.0 - Timing Side-Channel Authentication Bypass via strcmp
CVSS 9.8
CVE-2024-25190 CRITICAL
l8w8jwt 2.2.1 - Timing Side-Channel Authentication Bypass via memcmp
CVSS 9.8
CVE-2024-25189 CRITICAL
libjwt <1.15.3 - Auth Bypass
CVSS 9.8
CVE-2024-25146 MEDIUM
Liferay Portal/DXP - Info Disclosure
CVSS 5.3
CVE-2024-0202 MEDIUM
cryptlib < 3.4.7 - Timing Attack via RSA Key Exchange Ciphersuites
CVSS 5.9
CVE-2024-23170 MEDIUM
Mbed TLS 2.x < 2.28.7 and 3.x < 3.5.2 - Timing Side-Channel Attack via RSA Private Operations
CVSS 5.5
CVE-2024-0914 MEDIUM
opencryptoki < 3.23.0 - Timing Side-Channel in RSA PKCS#1 v1.5 Padding
CVSS 5.9
CVE-2024-21671 LOW
vantage6 < 4.2.0 - Observable Timing Discrepancy in Login Response
CVSS 3.7
Details
Vulnerabilities 751