PT-2026-81912 · Kimai · Kimai
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kimai versions prior to 2.54.0
Description
A timing oracle issue exists in the
TokenAuthenticator component. This allows unauthenticated attackers to perform username enumeration by analyzing response time differences, as the password hasher only executes for users that already exist in the system. This process is facilitated through the X-AUTH-USER header and is not mitigated by login throttling protections.Recommendations
Update to version 2.54.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimai