CVE-2023-49069: Medium severity mendix runtime vulnerability
A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.12 (All versions < V10.12.11 only if the basic authentication mechanism is used by the application), Mendix Runtime V10.6 (All versions < V10.6.19 only if the basic authentication mechanism is used by the application), Mendix Runtime V8 (All versions < V8.18.33 only if the basic authentication mechanism is used by the application), Mendix Runtime V9 (All versions < V9.24.31 only if the basic authentication mechanism is used by the application). The authentication mechanism of affected applications contains an observable response discrepancy vulnerability when validating usernames. This could allow unauthenticated remote attackers to distinguish between valid and invalid usernames.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49069?
CVE-2023-49069 has been classified as a high severity vulnerability.
How do I fix CVE-2023-49069?
To mitigate CVE-2023-49069, upgrade to Mendix Runtime V10.17.0 or later, V10.12.11 or later, or V10.6.19 or later.
Which versions of Mendix Runtime are affected by CVE-2023-49069?
CVE-2023-49069 affects Mendix Runtime V10 (all versions below 10.17.0), V10.12 (all versions below 10.12.11), and V10.6 (all versions below 10.6.19).
What authentication mechanism is related to CVE-2023-49069?
CVE-2023-49069 is specifically related to applications using the basic authentication mechanism.
Is there a workaround for CVE-2023-49069?
Currently, the only effective workaround for CVE-2023-49069 is to upgrade to a patched version of Mendix Runtime.