-
CVSS Score
-The vulnerability stems from timing differences in authentication responses between existing and non-existing users in the internal IdP. The fix commit 'Flatten response times' (PR #2472) specifically targeted this authentication flow. The test file InternalAuthBackendTests.java indicates the authentication backend implementation was modified. The authenticate() function would naturally handle user validation steps, where early-exit patterns for non-existent users would create measurable timing differences. The CWE-208 (Timing Discrepancy) classification strongly supports this being an authentication flow implementation issue.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.opensearch.plugin:opensearch-security | maven | < 1.3.9 | 1.3.9 |
| org.opensearch.plugin:opensearch-security | maven | >= 2.0.0, < 2.6.0 | 2.6.0 |
Ongoing coverage of React2Shell