
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-g84q-cq55-xwgp) is a member disclosure vulnerability in the Silverstripe Framework's login form, discovered and patched in May 2017. This security issue affects versions >= 3.4.0-rc1, < 3.4.6 and >= 3.5.0-rc1, < 3.5.4 of the silverstripe/framework package. The vulnerability was fixed in versions 3.4.6 and 3.5.4 (GitHub Advisory, Silverstripe Advisory).
The vulnerability is a user ID enumeration flaw in the brute force protection mechanism of the login system. The system behaved differently for existing versus non-existing users during login attempts, where users that didn't exist would never receive a lockout message, while existing users would get locked out after multiple failed attempts. This inconsistency in behavior created an information disclosure vector. The vulnerability has been assigned a CVSS v3.1 score of 5.3 (Moderate), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (GitHub Advisory).
The vulnerability allows attackers to infer or confirm the existence of user accounts in the member table through the different responses received during login attempts. This information disclosure could be used as part of a larger attack strategy, such as targeted brute force attacks against confirmed existing accounts (Silverstripe Advisory).
The vulnerability is exploitable remotely without requiring any privileges or user interaction. An attacker can simply attempt to login with different usernames and observe the system's responses to determine which accounts exist in the system (GitHub Advisory).
The issue has been resolved by ensuring that login attempt logging and lockout processes work equivalently for both existing and non-existent users. Users should upgrade to the patched versions: 3.4.6 or 3.5.4. The fix ensures that the lockout mechanism treats all login attempts consistently, regardless of whether the user exists in the database or not (GitHub Advisory, Silverstripe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."