Skip to content

Email enumeration in signup and login forms

Moderate
cuu508 published GHSA-frxj-v529-jv6w Jan 23, 2023

Package

healthchecks

Affected versions

< 2.6

Patched versions

2.6

Description

Impact

The signup and sign in forms are vulnerable to an email enumeration attack. Both forms return different responses for registered and unregistered email addresses. An attacker can use this to determine if a particular email address has an account.

Patches

The vulnerability is fixed in release v2.6.

References

The original report at huntr.dev: https://huntr.dev/bounties/208a096f-7986-4eed-8629-b7285348a686/

Severity

Moderate

CVE ID

CVE-2023-0440

Weaknesses

Credits