Skip to content

The "Forgot your password?" form offers too much information concerning user accounts

Moderate
tmortagne published GHSA-35fg-hjcr-j65f Feb 9, 2022

Package

maven org.xwiki.platform:xwiki-platform-web (Maven)

Affected versions

< 12.10.9, < 13.4.1, < 13.6RC1

Patched versions

12.10.9, 13.4.1, 13.6RC1

Description

Impact

It's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users.

Patches

The problem has been patched on XWiki 12.10.9, 13.4.1 and 13.6RC1.

Workarounds

There's no easy workaround other than applying the upgrade.

References

https://jira.xwiki.org/browse/XWIKI-18787

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

CVE-2022-23619

Weaknesses