Unrated severityNVD Advisory· Published Jan 10, 2022· Updated Sep 16, 2024
NocoDB - Observable Discrepancy in the password-reset feature
CVE-2022-22120
Description
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/nocodb/nocodb/commit/f46e89b0mitrex_refsource_MISC
- www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22120mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.