We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).
Reserved 2025-03-21 | Published 2025-03-21 | Updated 2025-03-21 | Assigner mitreCWE-208 Observable Timing Discrepancy
www.x41-dsec.de/lab/advisories/x41-2025-001-OpenSlides
Support options