Observable Response Discrepancy in Lost Password Service
Description
Published by the National Vulnerability Database
Sep 15, 2021
Reviewed
Sep 17, 2021
Published to the GitHub Advisory Database
Sep 20, 2021
Last updated
Feb 1, 2023
Impact
It is possible to enumerate usernames via the forgot password functionality
Patches
Update to version
10.1.3
or apply this patch manually: https://github.com/pimcore/pimcore/pull/10223.patchWorkarounds
Apply https://github.com/pimcore/pimcore/pull/10223.patch manually.
References