VulnerabilityModified
CVE-2017-5537
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
MEDIUM 5.3EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- weblate/weblate
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2017/01/18/11Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2017/01/20/1Mailing List, Patch
- http://www.securityfocus.com/bid/95676Third Party Advisory, VDB Entry
- https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rstPatch, Release Notes
- https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079Patch
- https://github.com/WeblateOrg/weblate/issues/1317Issue Tracking, Patch
- http://www.openwall.com/lists/oss-security/2017/01/18/11Mailing List, Patch
- http://www.openwall.com/lists/oss-security/2017/01/20/1Mailing List, Patch
- http://www.securityfocus.com/bid/95676Third Party Advisory, VDB Entry
- https://github.com/WeblateOrg/weblate/blob/weblate-2.10.1/docs/changes.rstPatch, Release Notes
- https://github.com/WeblateOrg/weblate/commit/abe0d2a29a1d8e896bfe829c8461bf8b391f1079Patch
- https://github.com/WeblateOrg/weblate/issues/1317Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.