GHSA-7789-65hx-f26w: FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel
The /api/auth/login authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a 401/403 response almost immediately. When a valid username is provided, the server performs a bcrypt password comparison, causing a measurable delay in the response time.
References
Code Behaviors & Features
Detect and mitigate GHSA-7789-65hx-f26w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →