The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079 | patch |
http://www.openwall.com/lists/oss-security/2017/01/18/11 | patch mailing list |
https://github.com/WeblateOrg/weblate/issues/1317 | patch issue tracking |
http://www.openwall.com/lists/oss-security/2017/01/20/1 | patch mailing list |
http://www.securityfocus.com/bid/95676 | third party advisory vdb entry |
https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rst | patch release notes |