github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2017-005-1.yaml GHSA-7M2V-X7RG-5HM5
silverstripe/framework vulnerable to user enumeration via timing attack on login and password reset forms
Description
User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
silverstripe/frameworkBrowse Packagist / silverstripe/framework | GitHub Advisory | 3.5.0-rc1 to < 3.5.5 · Fixed in 3.5.5 | affected |
| 3.6.0-rc1 to < 3.6.2 · Fixed in 3.6.2 | affected |
References
4github.com
https://github.com/silverstripe/silverstripe-framework github.com
https://github.com/silverstripe/silverstripe-framework/commit/f0262a8fd9ab5fb51b178ace3c3487351217f5a0 silverstripe.org
https://www.silverstripe.org/download/security-releases/ss-2017-005