Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96w6-55wg-2r8g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.

The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.

EPSS

Процентиль: 42%
0.00203
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 9 лет назад

The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.

CVSS3: 3.7
nvd
почти 9 лет назад

The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.

CVSS3: 3.7
debian
почти 9 лет назад

The password reset functionality in ownCloud Server before 8.1.11, 8.2 ...

EPSS

Процентиль: 42%
0.00203
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200