{ "schema_version": "1.4.0", "id": "GHSA-f8pq-r7mv-pvxm", "modified": "2022-05-24T17:40:55Z", "published": "2022-05-24T17:40:55Z", "aliases": [ "CVE-2020-9389" ], "details": "A username enumeration issue was discovered in SquaredUp before version 4.6.0. The login functionality was implemented in a way that would enable a malicious user to guess valid username due to a different response time from invalid usernames.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9389" }, { "type": "WEB", "url": "https://support.squaredup.com/hc/en-us/articles/360017255858" }, { "type": "WEB", "url": "https://support.squaredup.com/hc/en-us/articles/360019427238-CVE-2020-9389-Username-enumeration-possible-via-a-timing-attack" } ], "database_specific": { "cwe_ids": [ "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-02-03T20:15:00Z" } }