In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the email address is associated with any account. This allows remote attackers to enumerate accounts via a series of requests.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-01-10T00:00:00
Updated: 2024-08-03T06:48:35.813Z
Reserved: 2022-05-07T00:00:00
Link: CVE-2022-30332
Vulnrichment
Updated: 2024-08-03T06:48:35.813Z
NVD
Status : Modified
Published: 2023-01-10T21:15:11.520
Modified: 2024-11-21T07:02:36.457
Link: CVE-2022-30332
Redhat
No data.