CVE-2022-34623 Information

Description

Mealie1.0.0beta3 is vulnerable to user enumeration via timing response discrepancy between users and non-users when an invalid password message is displayed during an authentication attempt.

Reference

https://gainsec.com/2022/08/19/cve-2022-34615-cve-2022-34621-cve-2022-34623-cve-2022-34624/ https://cwe.mitre.org/data/definitions/204.html https://docs.mealie.io/changelog/v0.5.6/ https://hub.docker.com/r/hkotel/mealie

Share on: