CVE-2022-39314 - CVE House
Back to Database
Status published Medium CVE-2022-39314

User enumeration in the code-based login and password reset forms

Vulnerability Description

Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeration due to Improper Restriction of Excessive Authentication Attempts. This vulnerability affects you only if you are using the `code` or `password-reset` auth method with the `auth.methods` option or if you have enabled the `debug` option in production. By using two or more IP addresses and multiple login attempts, valid user accounts will lock, but invalid accounts will not, leading to account enumeration. This issue has been patched in versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1. If you cannot update immediately, you can work around the issue by setting the `auth.methods` option to `password`, which disables the code-based login and password reset forms.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-39314

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

kirby
Vulnerable Versions:
>= 3.5.0, < 3.5.8.2, >= 2.6.0, < 3.6.6.2, >= 3.7.0, <3.7.5.1, >= 3.8.0, < 3.8.1

Timeline

Official Publish: October 24th, 2022
Last Modified: January 30th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)