Description
Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1981 | Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually. |
Github GHSA |
GHSA-579x-cjvr-cqj9 | Observable Response Discrepancy in Lost Password Service |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T01:58:18.264Z
Reserved: 2021-08-16T00:00:00.000Z
Link: CVE-2021-39189
No data.
Status : Modified
Published: 2021-09-15T14:15:08.997
Modified: 2024-11-21T06:18:50.407
Link: CVE-2021-39189
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA