Description
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.
No analysis available yet.
Remediation
Vendor Solution
Update to version 0.84.0 or later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27269 | In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses. |
References
History
Tue, 26 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nocodb
Nocodb nocodb |
|
| CPEs | cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xgenecloud
Xgenecloud nocodb |
Nocodb
Nocodb nocodb |
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-16T23:27:02.597Z
Reserved: 2021-12-21T00:00:00.000Z
Link: CVE-2022-22120
No data.
Status : Modified
Published: 2022-01-10T16:15:10.180
Modified: 2025-08-26T18:50:20.227
Link: CVE-2022-22120
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD