← Back

CVE-2022-48366

nvd nist
Published: Mar 12, 2023Modified: Mar 4, 2025

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.2 / Impact: 1.4
Source: NVD

Description

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.

Affected (15)

7 products
Commerce
Digital Experience Platform
Ez Platform
Ez Platform Kernel
Ezplatform Page Builder
Jmspaymentcorebundle
Kernel
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Ibexa
From 2.5.0 to 2.5.13
From 3.3.0 to 3.3.18
From 4.0.0 to 4.0.7
From 4.1.0 to 4.1.4
Ibexa
From 3.3.0 to 3.3.20
From 4.0.0 to 4.0.7
From 4.1.0 to 4.1.4
Before 2.5.30
Ibexa
From 1.3.0 to 1.3.19
From 7.5.0 to 7.5.29
Ibexa
From 1.3.0 to 1.3.27
From 2.3.0 to 2.3.19
From 3.0.0 to 3.0.2
Ibexa
From 4.0.0 to 4.0.7
From 4.1.0 to 4.1.4

Timeline

No history available yet.