Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: dokuwiki

Found 1 matching suggestions

View:
Compact
Detailed
Permalink CVE-2019-25338
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 1 month, 1 week ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed
    3 packages
    • python312Packages.dokuwiki
    • python313Packages.dokuwiki
    • python314Packages.dokuwiki
  • @LeSuisse dismissed
Dokuwiki 2018-04-22b - Username Enumeration

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.

Affected products

Dokuwiki
  • ==2018-04-22b "Greebo"

Matching in nixpkgs

Package maintainers

Current stable branch was never impacted: https://github.com/NixOS/nixpkgs/commit/c5959065a18f28fd6ddab81a68727927bfac77c0