CVE-2022-48366: Timing attack in eZ Platform Ibexa
(updated )
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
References
- developers.ibexa.co/security-advisories/ibexa-sa-2022-006-vulnerabilities-in-page-builder-login-and-commerce
- github.com/advisories/GHSA-66m4-gc8h-hpjx
- github.com/ezsystems/ezplatform-kernel/security/advisories/GHSA-342c-vcff-2ff2
- github.com/ezsystems/ezpublish-kernel/security/advisories/GHSA-xfqg-p48g-hh94
- nvd.nist.gov/vuln/detail/CVE-2022-48366
Detect and mitigate CVE-2022-48366 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →