Description
Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time.
No analysis available yet.
Remediation
Vendor Solution
Update to OTRS 8.0.23 or OTRS 7.0.35.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35807 | Attacker is able to determine if the provided username exists (and it's valid) using Request New Password feature, based on the response time. |
References
History
Mon, 16 Sep 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Information disclosure in Request New Password feature | Information disclosure in Request New Password feature |
Status: PUBLISHED
Assigner: OTRS
Published:
Updated: 2024-09-16T16:43:46.120Z
Reserved: 2022-06-09T00:00:00.000Z
Link: CVE-2022-32741
No data.
Status : Modified
Published: 2022-06-13T08:15:19.083
Modified: 2024-11-21T07:06:52.127
Link: CVE-2022-32741
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD