Overview
The OpenAtlas login form revealed whether a username existed by returning different error messages. This allowed valid accounts to be enumerated without knowing any passwords.
Technical findings
OpenAtlas responded differently to failed logins depending on whether the account existed, making it relatively easy to identify valid usernames.
This does not directly enable account takeover, but a verified username list removes uncertainty for attackers and improves their prospects for password spraying, credential stuffing and phishing.
The fix standardizes login responses so that error messages no longer reveal whether the username or password was incorrect.
Why it matters
An attacker can automatically try possible usernames and compare the responses. That does not compromise an account by itself, but it makes password spraying, credential stuffing and targeted phishing significantly easier.
Potential impact
- Enables valid-username enumeration, facilitating brute-force attacks, credential stuffing and phishing.
Remediation
- Upgrade to OpenAtlas 8.12.1 or later.
- Return the same generic error message for all failed login attempts.
- Normalize response times and HTTP behavior as well to prevent alternative enumeration signals.
- Implement rate limiting and monitoring for repeated failed logins.
Affected and fixed versions
Disclosure timeline
- Discovery
Discovered during an on-premises penetration test.
- Initial contact
Contacted the OpenAtlas team about the disclosure process.
- Delivery coordinated
Agreed on a communication channel for the technical report.
- Report sent
Submitted the complete report to the vendor.
- Fix confirmation
The vendor confirmed the fix.
- CVE assignment
Received the CVE ID during the disclosure process.