SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-22120

In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature.

MEDIUM 5.3EPSS 1.37%

Does this matter?

Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.

Description

In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.37% probability · 70th percentile
CISA KEV
Not listed
Weakness
CWE-203
Affected
nocodb/nocodb
Source
vulnerabilitylab@mend.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.