The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234.
History

Wed, 19 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Mar 2025 15:45:00 +0000

Type Values Removed Values Added
Description The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published: 2025-03-19T15:27:55.960Z

Updated: 2025-03-19T17:33:43.814Z

Reserved: 2025-02-11T08:24:51.660Z

Link: CVE-2025-26485

cve-icon Vulnrichment

Updated: 2025-03-19T17:33:39.933Z

cve-icon NVD

Status : Received

Published: 2025-03-19T16:15:31.257

Modified: 2025-03-19T16:15:31.257

Link: CVE-2025-26485

cve-icon Redhat

No data.