GHSA-wmwf-49vv-p3mr

    Dashboard / Vulnerabilities / GHSA-wmwf-49vv-p3mr

    GHSA-wmwf-49vv-p3mr

    Published: 3 Aug 2023Last Modified: 10 Sept 2026

    Summary: Sulu Observable Response Discrepancy on Admin Login

    Details: ### Impact It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Impacted by this issue are Sulu installation >= 2.5.0 and <2.5.10 using the newer Symfony Security System which is default since Symfony 6.0 but can be enabled in Symfony 5.4. Sulu Installation not using the old Symfony 5.4 security System and previous version are not impacted by this Security issue. ### Patches The problem has been patched in version 2.5.10. ### Workarounds Create a custom AuthenticationFailureHandler which does not return the `$exception->getMessage();` instead the `$exception->getMessageKey();` ### References Currently no references.

    Affected packages

    Package

    Name: sulu/sulu

    Purl: pkg:composer/sulu/sulu

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.5.0
    Fixed -2.5.10

    Affected versions

    2.5.0
    2.5.1
    2.5.2
    2.5.3
    2.5.4
    2.5.5
    2.5.6
    2.5.7
    2.5.8
    2.5.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wmwf-49vv-p3mr | CVE-DB