First published: Fri Mar 21 2025(Updated: )
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSlides | <4.2.5 | |
OpenSlides | <4.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30344 is classified as a moderate severity vulnerability due to the potential for user enumeration.
To fix CVE-2025-30344, upgrade to OpenSlides version 4.2.5 or later where this issue has been resolved.
CVE-2025-30344 is a timing attack vulnerability that allows for user enumeration during the login process.
OpenSlides versions prior to 4.2.5 are affected by CVE-2025-30344.
The risks include unauthorized users being able to determine valid usernames, leading to targeted attacks.