Security Advisory: User-Enumeration attack (Malformed username)
Date: 27. 01. 2025
Severity: 5.3 (Medium)
Affected versions: All midPoint versions prior to 4.8.5, 4.9
Fixed in versions: 4.8.6, 4.9.1
Description
An attacker uses a malformed username and incorrect password to log in to midPoint. MidPoint normalizes the name and searches for the user by name. If the user exists, it will redirect the attacker back to the login page with an error that the name or password is incorrect. If the user does not exist in the midpoint, the attacker is redirected to the 'Internal server error' page with status 500.
Severity and Impact
This is Medium Severity Issue.
The attacker gets information if there is a user with a normalized username.
Mitigation
Users of affected MidPoint versions are advised to upgrade their deployments to the latest maintenance releases.
Was this page helpful?
YES
NO
Thanks for your feedback