CVE-2022-32425: Medium severity mealie vulnerability
Published Jul 14, 2022
·Updated
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.
Affected Software
1 affected component
Mealie Mealie=1.0.0-beta2
Event History
Jul 14, 2022
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32425?
CVE-2022-32425 has a medium severity rating due to the potential for user enumeration attacks.
2
How do I fix CVE-2022-32425?
To fix CVE-2022-32425, it's recommended to update Mealie to a version that mitigates the timing attack vulnerability.
3
What is the impact of CVE-2022-32425?
CVE-2022-32425 allows attackers to determine existing usernames by analyzing the server's response times during login attempts.
4
Who is affected by CVE-2022-32425?
Users running Mealie version 1.0.0-beta2 are affected by CVE-2022-32425.
5
What type of attack is enabled by CVE-2022-32425?
CVE-2022-32425 enables timing attacks that allow for user enumeration, increasing the risk of unauthorized access.