Описание
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
Ссылки
- Technical Description
- Third Party Advisory
- Broken LinkRelease NotesVendor Advisory
- Technical Description
- Third Party Advisory
- Broken LinkRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:talend:administration_center:7.3.1:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00377
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-203
CWE-203
Связанные уязвимости
CVSS3: 5.3
github
около 3 лет назад
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
EPSS
Процентиль: 59%
0.00377
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-203
CWE-203