Cockpit CMS before 2.14.1 Account Enumeration via Auth Timing
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.9epss 0.2%
probabilidade de exploração
0.2%top 84% das CVEs
exploração observada
nãonenhuma fonte reporta
Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which accounts exist by observing that existing accounts trigger bcrypt verification while non-existent accounts return immediately.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
cockpit-hq · cockpitReferências
https://github.com/Cockpit-HQ/Cockpithttps://github.com/Cockpit-HQ/Cockpit/blob/2.14.0/modules/App/Controller/Auth.phphttps://github.com/Cockpit-HQ/Cockpit/commit/5d65ae7b63a261a63e8809e5fba857ef3eadb2achttps://link.mateocallec.com/MFC-2026-001https://www.vulncheck.com/advisories/cockpit-cms-before-2.14.1-account-enumeration-via-auth-timing