Junglewise Threat Intelligence

CVE-2025-9031: DivvyDrive Web timing discrepancy in search functionality

CVE-2025-9031 · Severity: medium · CVSS 4.3 · Published 2025-09-24

Executive brief

DivvyDrive Web, a web-based file storage and management platform, is affected by a security flaw that could allow unauthorized users to infer the existence of specific data. By measuring the time it takes for the system to respond to search queries, an attacker can potentially determine if certain files or information exist within the system. This could lead to a minor leak of sensitive information regarding the contents of the database.

Technical details

A timing side-channel vulnerability (CWE-208) exists in DivvyDrive Web versions 4.8.2.2 through 4.8.2.14. The application's search functionality exhibits observable timing discrepancies when processing queries, which can be exploited to perform cross-domain search timing attacks. An authenticated attacker with network access can measure these response time differences to infer the presence or absence of specific records or files. The vulnerability is addressed in version 4.8.2.15.

Affected products

  • DivvyDrive Information Technologies Inc. DivvyDrive Web from 4.8.2.2 before 4.8.2.15

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory

References