Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-34700

Forgotten password features leaks information to the user that could be used to gain unauthorised access to Confluence

XMLWordPrintable

      Using the forgotten password feature in Confluence it is possible to find out which email addresses are stored in the system from the responses given from the form when submitted.

      These responses need to be made generic so that it is not possible to tell which email addresses are or are not stored in the database.

        1. bademail.png
          bademail.png
          33 kB
        2. genericerror.png
          genericerror.png
          29 kB
        3. genericyes.png
          genericyes.png
          20 kB

            mtang Minh Tang (Inactive)
            shaffenden Steve Haffenden (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: