PT-2017-16566 · Weblate · Weblate

Jelly

·

Published

2017-03-15

·

Updated

2022-05-17

·

CVE-2017-5537

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 2.10.1
Description The issue concerns the password reset form, which provides different error messages based on whether an email address is associated with an account. This allows remote attackers to enumerate user accounts by sending a series of requests.
Recommendations For versions prior to 2.10.1, update to version 2.10.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the password reset form to minimize the risk of exploitation.

Fix

Information Disclosure

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5537
GHSA-J24G-GM76-J829
PYSEC-2017-42

Affected Products

Weblate