CVE-2025-26485

A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong password or a non existent user). The difference in the returned error messages could be used by attackers to understand whether a certain user is registered in the Identity Manager. This issue affects Life 1st: 1.5.2.14234.
Configurations

No configuration.

History

02 Jul 2025, 15:15

Type Values Removed Values Added
References
  • () https://euvd.enisa.europa.eu/vulnerability/CVE-2025-26485 -
Summary
  • (es) La vulnerabilidad "Exposición de información confidencial a un agente no autorizado" que afecta a Life 1st Identity Manager (versión Beta80) permite la enumeración de usuarios mediante las API Rest de autenticación. Afectado: Life 1st, versión 1.5.2.14234. Se muestran diferentes mensajes de error en los intentos fallidos de autenticación si se utiliza una contraseña incorrecta o un usuario inexistente. Este problema afecta a Life 1st: versión 1.5.2.14234.
Summary (en) The Exposure of Sensitive Information to an Unauthorized Actor vulnerability impacting Beta80 Life 1st Identity Manager allows User Enumeration using Authentication Rest APIs. Affected: Life 1st version 1.5.2.14234. Different error messages are returned to failed authentication attempts in case of the usage of a wrong password or a non existent user. This issue affects Life 1st: 1.5.2.14234. (en) A vulnerability in Beta80 Life 1st enables the retrieval of different error messages for failed authentication attempts (in case of the usage of a wrong password or a non existent user). The difference in the returned error messages could be used by attackers to understand whether a certain user is registered in the Identity Manager. This issue affects Life 1st: 1.5.2.14234.

19 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-19 16:15

Updated : 2025-07-02 15:15


NVD link : CVE-2025-26485

Mitre link : CVE-2025-26485

CVE.ORG link : CVE-2025-26485


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor