github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2025-001.yaml GHSA-256Q-HX8W-XCQX
Silverstripe Framework user enumeration via timing attack on login and password reset forms
Description
### Impact User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials. This was originally disclosed in https://www.silverstripe.org/download/security-releases/ss-2017-005/ for CMS 3 but was not patched in CMS 4+ ### References - https://www.silverstripe.org/download/security-releases/ss-2017-005 - https://www.silverstripe.org/download/security-releases/ss-2025-001
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 4.0.0 to < 5.3.23 · Fixed in 5.3.23 | affected |
References
7github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/pull/11681 github.com
https://github.com/silverstripe/silverstripe-framework/security/advisories/GHSA-256q-hx8w-xcqx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-12849 silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2017-005 silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2025-001