SCA: security update for ethyca-fides (GHSA-2h46-8gf5-fmxv)

medium Tenable Cloud Security Plugin ID 408931

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username
enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows an
unauthenticated attacker to determine the existence of valid usernames by analyzing the time it takes for
the server to respond to login requests. The discrepancy in response times between valid and invalid
usernames can be leveraged to enumerate users on the system. This vulnerability enables a timing-based
username enumeration attack. An attacker can systematically guess and verify which usernames are valid by
measuring the server's response time to authentication requests. This information can be used to conduct
further attacks on authentication such as password brute-forcing and credential stuffing. The
vulnerability has been patched in Fides version `2.44.0`. Users are advised to upgrade to this version or
later to secure their systems against this threat. There are no workarounds. (CVE-2024-45052)

See Also

https://github.com/advisories/GHSA-2h46-8gf5-fmxv

Plugin Details

Severity: Medium

ID: 408931

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-45052

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/4/2024

Vulnerability Publication Date: 9/4/2024

Reference Information

CVE: CVE-2024-45052

cwe: CWE-208