Timing-Based Username Enumeration in Fides Webserver Authentication
CVE-2024-45052
5.3MEDIUM
What is CVE-2024-45052?
The Fides webserver prior to version 2.44.0 contains a timing-based vulnerability that allows unauthenticated attackers to efficiently determine valid usernames. By analyzing the varying response times of the server to login attempts, an attacker can ascertain which usernames exist within the system. This issue opens avenues for further exploitation, including password brute-forcing and credential stuffing attacks. Users are strongly encouraged to upgrade to version 2.44.0 or later to mitigate this vulnerability, as no effective workarounds are available.
