Описание
ibexa/user login enumerates user accounts
Impact
In v5, error messages could provide enough information to tell whether a user exists or not. This is resolved by ensuring the error messages are sufficiently ambigious.
Patches
See "Patched versions".
Workarounds
None.
Resources
Пакеты
Наименование
ibexa/user
composer
Затронутые версииВерсия исправления
>= 5.0.0, < 5.0.3
5.0.3
6.9 Medium
CVSS4
Дефекты
CWE-209
6.9 Medium
CVSS4
Дефекты
CWE-209