taskcafe icon indicating copy to clipboard operation
taskcafe copied to clipboard

User enumeration possible due to time difference

Open 6en6ar opened this issue 8 months ago • 0 comments

Describe the bug The /auth/login takes longer time to process correct usernames than incorrect ones leading to possible user enumeration. There is a ≈700ms difference between the username check and password check

Expected behavior The login should not take longer for correct usernames since it can be used to probe for valid accounts.

Screenshots / Live demo link

Image

Image

6en6ar avatar May 07 '25 17:05 6en6ar