CVE-2022-22120 Information

Description

In NocoDB versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address the application displays an error message when the email isn’t registered within the system. This allows attackers to enumerate the registered users’ email addresses.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22120 https://github.com/nocodb/nocodb/commit/f46e89b0

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

Share on: