VYPR

CWE-203

Observable Discrepancy

BaseIncomplete

Description

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-189

CVEs mapped to this weakness (762)

page 29 of 39
  • CVE-2026-23849MedJan 19, 2026
    risk 0.27cvss 5.3epss 0.00

    File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid…

  • CVE-2026-23511MedJan 15, 2026
    risk 0.27cvss 5.3epss 0.00

    ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has been discovered in Zitadel's login interfaces. An unauthenticated attacker can exploit this flaw to confirm the existence of valid user accounts by iterating…

  • CVE-2025-43786MedSep 9, 2025
    risk 0.27cvss 5.3epss 0.00

    Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the…

  • CVE-2025-43751MedAug 22, 2025
    risk 0.27cvss 5.3epss 0.00

    User enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.14, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10 and 7.4 GA…

  • CVE-2024-54002MedDec 4, 2024
    risk 0.27cvss 5.3epss 0.00

    Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than…

  • CVE-2024-45678MedSep 3, 2024
    risk 0.27cvss 4.2epss 0.00

    Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a…

  • CVE-2024-1543MedAug 29, 2024
    risk 0.27cvss 4.1epss 0.00

    The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment such as Intel SGX, an attacker can gain a per instruction sub-cache-line resolution allowing them to…

  • CVE-2024-41880MedJul 22, 2024
    risk 0.27cvss 5.3epss 0.00

    In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

  • CVE-2024-26268MedFeb 20, 2024
    risk 0.27cvss 5.3epss 0.01

    User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to determine if an account exist in…

  • CVE-2023-41885MedSep 12, 2023
    risk 0.27cvss 5.3epss 0.00

    Piccolo is an ORM and query builder which supports asyncio. In versions 0.120.0 and prior, the implementation of `BaseUser.login` leaks enough information to a malicious user such that they would be able to successfully generate a list of valid users on the platform. As Piccolo…

  • CVE-2023-39522MedAug 29, 2023
    risk 0.27cvss 5.3epss 0.01

    goauthentik is an open-source Identity Provider. In affected versions using a recovery flow with an identification stage an attacker is able to determine if a username exists. Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a…

  • CVE-2021-46876MedMar 12, 2023
    risk 0.27cvss 5.3epss 0.01

    An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.

  • CVE-2023-25806MedMar 2, 2023
    risk 0.27cvss 5.3epss 0.00

    OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time between calls where the user provided exists and calls where it does not. This issue only affects calls…

  • CVE-2022-39228MedMar 1, 2023
    risk 0.27cvss 5.3epss 0.01

    vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the username actually exists. This is an attempt to prevent bots from obtaining usernames. However, if a…

  • CVE-2019-14353MedAug 8, 2019
    risk 0.27cvss 4.2epss 0.00

    On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the…

  • CVE-2018-5407MedNov 15, 2018
    risk 0.27cvss 4.7epss 0.03

    Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

  • CVE-2026-73409MedAug 12, 2026
    risk 0.26cvss epss 0.00

    Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through…

  • CVE-2024-8992MedDec 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2023-50306MedFeb 20, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

  • CVE-2023-25000MedMar 30, 2023
    risk 0.26cvss 5.0epss 0.00

    HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the…