Lucene search

K
osvGoogleOSV:CVE-2022-22120
HistoryJan 10, 2022 - 4:15 p.m.

CVE-2022-22120

2022-01-1016:15:10
Google
osv.dev
8
nocodb
vulnerable
password-reset
enumeration
observable discrepancy
email addresses

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

39.3%

In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn’t registered within the system. This allows attackers to enumerate the registered users’ email addresses.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

39.3%

Related for OSV:CVE-2022-22120