mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #12804
[Bug 1203924] [NEW] Bruteforce user enumeration vuln in password reset screen
*** This bug is a security vulnerability ***
Public security bug reported:
A user enumeration vulnerability means that an attacker can get a list
of legal usernames and/or email addresses from the site. A "bruteforce"
user enumeration vulnerability means that if they have a list of
potential usernames and/or email addresses, they can verify whether or
not each of them is registered with an account in the site.
The Mahara password reset page is vulnerable to this. You can simply go
in to https://mahara.org/forgotpass.php and enter username or email
after username or email, and get a friendly response indicating whether
each one is registered with a user in the site or not.
** Affects: mahara
Importance: Medium
Status: Triaged
** Tags: privacy security
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contrib members
https://bugs.launchpad.net/bugs/1203924
Title:
Bruteforce user enumeration vuln in password reset screen
Status in Mahara ePortfolio:
Triaged
Bug description:
A user enumeration vulnerability means that an attacker can get a list
of legal usernames and/or email addresses from the site. A
"bruteforce" user enumeration vulnerability means that if they have a
list of potential usernames and/or email addresses, they can verify
whether or not each of them is registered with an account in the site.
The Mahara password reset page is vulnerable to this. You can simply
go in to https://mahara.org/forgotpass.php and enter username or email
after username or email, and get a friendly response indicating
whether each one is registered with a user in the site or not.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1203924/+subscriptions
Follow ups
-
[Bug 1203924] Re: Username enumeration vulnerability via login & password reset screens
From: Robert Lyon, 2018-01-09
-
[Bug 1203924] Re: Mahara contains no protections against enumeration attacks
From: Aaron Wells, 2016-01-13
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2015-10-23
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2015-04-21
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Son Nguyen, 2015-04-19
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Robert Lyon, 2015-04-17
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2014-09-10
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2014-05-13
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Robert Lyon, 2014-04-03
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Robert Lyon, 2014-03-27
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Kristina Hoeppner, 2014-03-24
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2014-02-24
-
[Bug 1203924] A patch has been submitted for review
From: Mahara Bot, 2014-02-23
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2014-01-14
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Leo Xiong, 2014-01-14
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2013-12-16
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2013-10-04
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2013-10-01
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2013-09-30
-
[Bug 1203924] Re: Bruteforce username/email enumeration vuln in password reset screen
From: Aaron Wells, 2013-09-10
-
[Bug 1203924] Re: Bruteforce user enumeration vuln in password reset screen
From: Aaron Wells, 2013-07-23
-
[Bug 1203924] Re: Bruteforce user enumeration vuln in password reset screen
From: Aaron Wells, 2013-07-23
-
[Bug 1203924] [NEW] Bruteforce user enumeration vuln in password reset screen
From: Aaron Wells, 2013-07-23
References