Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-579x-cjvr-cqj9

Опубликовано: 20 сент. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Observable Response Discrepancy in Lost Password Service

Impact

It is possible to enumerate usernames via the forgot password functionality

Patches

Update to version 10.1.3 or apply this patch manually: https://github.com/pimcore/pimcore/pull/10223.patch

Workarounds

Apply https://github.com/pimcore/pimcore/pull/10223.patch manually.

Пакеты

Наименование

pimcore/pimcore

composer
Затронутые версииВерсия исправления

< 10.1.3

10.1.3

EPSS

Процентиль: 5%
0.0002
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204

Связанные уязвимости

CVSS3: 5.3
nvd
больше 4 лет назад

Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

EPSS

Процентиль: 5%
0.0002
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-203
CWE-204