The reset password form reveal users email address
Moderate severity
GitHub Reviewed
Published
Jul 1, 2021
in
xwiki/xwiki-platform
•
Updated Jan 29, 2023
Package
Affected versions
>= 13.1, < 13.2
Patched versions
13.2
Description
Published by the National Vulnerability Database
Jul 1, 2021
Reviewed
Jul 2, 2021
Published to the GitHub Advisory Database
Jul 2, 2021
Last updated
Jan 29, 2023
Impact
The reset password form reveals the email address of users just by giving their username.
Patches
The problem has been patched on XWiki 13.2RC1.
Workarounds
It's possible to manually modify the
resetpasswordinline.vm
to perform the changes made in xwiki/xwiki-platform@0cf7162#diff-14a3132e3986b1f5606dd13d9d8a8bb8634bec9932123c5e49e9604cfd850fc2References
https://jira.xwiki.org/browse/XWIKI-18400
For more information
If you have any questions or comments about this advisory:
References