Description
In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
References
https://cwe.mitre.org/data/definitions/204.html
Technical Description
https://excellium-services.com/cert-xlm-advisory/CVE-2022-30332
Third Party Advisory
https://help.talend.com/r/62tbPt7y~tPTxAB7y7KpeQ/H45WqEF32geNEZiGJnRwmw
Broken LinkRelease NotesVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
5.3 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Modified
Published
2023-01-10T21:15:11.520
2 years agoLast modified
2024-07-03T01:38:27.583
10 months ago