We found results for “”
WS-2022-0450
Date: August 23, 2022
User Enumeration via Response Timing was discovered in heroiclabs/nakama through 3.15.0. There is a significant timing difference in the login functionality of the Nakama Console for valid and invalid email addresses or usernames. An attacker is able to identify valid email addresses and usernames. This could allow for further attacks such as brute force attacks on valid accounts.
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Observable Response Discrepancy
CWE-204CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | LOW |
Integrity (I): | NONE |
Availability (A): | NONE |