An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ezsystems/ezplatform-kernel(Packagist) | 1.3.0 | 1.3.19 | N/A |
| ezsystems/ezpublish-kernel(Packagist) | 7.5.0 | 7.5.29 | N/A |
CVSS Metrics