Headline
GHSA-vjxx-jgcx-9fq2: Pixelfed allows user enumeration via reset password functionality
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed 0.11.4 and prior.
Pixelfed allows user enumeration via reset password functionality
Moderate severity GitHub Reviewed Published Feb 18, 2023 to the GitHub Advisory Database • Updated Feb 22, 2023
Related news
CVE-2023-0901: huntr – Security Bounties for any GitHub repository
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.