Hi @Silverhand-tw and the Logto team,
A second coordinated security disclosure (separate from #8772). I identified an information-disclosure issue in the experience password-verification flow (packages/core/src/libraries/user.ts verifyUserPassword). To avoid disclosing the bug class on a public issue, this thread is intentionally light on detail.
Same routing question as #8772 — please either enable PVR or share a security contact email and I will send the report privately. CC contact@logto.io.
This is the same bug class previously disclosed against zitadel as GHSA-jq8w-8q2f-ffm9 and GHSA-83cg-9mwq-gj42, included for context.
Reporter: edding.suree@gmail.com
Reference: LOGTO-002 (TS top-50 audit campaign)
Thanks!
Hi @Silverhand-tw and the Logto team,
A second coordinated security disclosure (separate from #8772). I identified an information-disclosure issue in the experience password-verification flow (
packages/core/src/libraries/user.tsverifyUserPassword). To avoid disclosing the bug class on a public issue, this thread is intentionally light on detail.https://github.com/eddieran/logto/tree/security/logto-002-password-timing-enum
(commit: equalize response budget on unknown-user path)
Same routing question as #8772 — please either enable PVR or share a security contact email and I will send the report privately. CC
contact@logto.io.This is the same bug class previously disclosed against zitadel as
GHSA-jq8w-8q2f-ffm9andGHSA-83cg-9mwq-gj42, included for context.Reporter: edding.suree@gmail.com
Reference: LOGTO-002 (TS top-50 audit campaign)
Thanks!