Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vjxx-jgcx-9fq2: Pixelfed allows user enumeration via reset password functionality

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed 0.11.4 and prior.

ghsa
#git#auth

Pixelfed allows user enumeration via reset password functionality

Moderate severity GitHub Reviewed Published Feb 18, 2023 to the GitHub Advisory Database • Updated Feb 22, 2023

Related news

CVE-2023-0901: huntr – Security Bounties for any GitHub repository

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.