We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-30344



Description

An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).

Reserved 2025-03-21 | Published 2025-03-21 | Updated 2025-03-21 | Assigner mitre


MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-208 Observable Timing Discrepancy

Product status

Default status
unaffected

Any version before 4.2.5
affected

References

www.x41-dsec.de/lab/advisories/x41-2025-001-OpenSlides

cve.org (CVE-2025-30344)

nvd.nist.gov (CVE-2025-30344)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-30344

Support options

Helpdesk Chat, Email, Knowledgebase