RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
The check_sign_in_key() function in the course/auth.py file compares login keys in a way that is vulnerable to timing attacks (CWE-208). An attacker, by sending appropriately crafted requests and measuring server response times, can gradually guess the correct key value character by character. The vulnerability does not require authentication or user interaction, however its effective exploitation requires appropriate network conditions (high attack complexity).
Successful exploitation of this vulnerability allows an attacker to guess the secret login key, which may lead to unauthorized access to the system with potentially serious consequences for the confidentiality, integrity, and availability of course data and user information.
The RELATE installation should be updated to a version containing commit 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb or later. Details are available in the project references on GitHub (GHSA-78j7-9xr9-2728).
All versions of the RELATE system prior to commit 2f68e16 (project available at github.com/inducer/relate)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HInducer Relate
APPInducer< 2026-04-17
Related vulnerabilities
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker...
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted pa...
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers...
Podatność Cross Site Scripting w inducer relate przed wersją 2024.1 umożliwia zdalnemu atakującemu eskalację u...