CVE-2022-32425

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/07/2022
Last modified:
20/07/2022

Description

The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mealie:mealie:1.0.0:beta2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools