OpenSlides 4.0.15 Vulnerability in Password Hash Verification
CVE-2024-22893
7.5HIGH
What is CVE-2024-22893?
The OpenSlides 4.0.15 version is susceptible to a vulnerability in its password verification process. By utilizing a content-dependent function during the password hash comparison, attackers can exploit timing discrepancies to infer information about the hashed passwords. This vulnerability enables the possibility of a timing attack, potentially compromising user accounts by revealing sensitive information related to password hashes.
