Security Advisory: User-Enumeration attack (Malformed username)

Last modified 27 Jan 2025 13:01 +01:00

Date: 27. 01. 2025

Severity: 5.3 (Medium)

Affected versions: All midPoint versions prior to 4.8.5, 4.9

Fixed in versions: 4.8.6, 4.9.1

Description

An attacker uses a malformed username and incorrect password to log in to midPoint. MidPoint normalizes the name and searches for the user by name. If the user exists, it will redirect the attacker back to the login page with an error that the name or password is incorrect. If the user does not exist in the midpoint, the attacker is redirected to the 'Internal server error' page with status 500.

Severity and Impact

This is Medium Severity Issue.

The attacker gets information if there is a user with a normalized username.

Mitigation

Users of affected MidPoint versions are advised to upgrade their deployments to the latest maintenance releases.

Was this page helpful?
YES NO
Thanks for your feedback