Answer in brief
CVE-2023-39522 records a Medium severity security vulnerability in Withdrawn Advisory: Username enumeration attack in goauthentik. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Answer in brief
CVE-2023-39522 records a Medium severity security vulnerability in Withdrawn Advisory: Username enumeration attack in goauthentik. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Update @goauthentik/api to 2023.6.2; @goauthentik/api to 2023.5.6 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2023-39522 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| @goauthentik/apinpm | >=2023.6.0,<2023.6.2 | 2023.6.2 |
| @goauthentik/apinpm | <2023.5.6 | 2023.5.6 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2023-39522 records a Medium severity security vulnerability in Withdrawn Advisory: Username enumeration attack in goauthentik. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for @goauthentik/api, @goauthentik/api.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate @goauthentik/api to 2023.6.2; @goauthentik/api to 2023.5.6 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2023-39522 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| @goauthentik/apinpm | >=2023.6.0,<2023.6.2 | 2023.6.2 |
| @goauthentik/apinpm | <2023.5.6 | 2023.5.6 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2023-39522 records a Medium severity security vulnerability in Withdrawn Advisory: Username enumeration attack in goauthentik. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for @goauthentik/api, @goauthentik/api.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard### Withdrawn Advisory This advisory has been withdrawn due to an incorrect package mapping error. This link is maintained to preserve external references. ### Original Description ## Summary Using a recovery flow with an identification stage an attacker is able to determine if a username exists. ## Impact Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above is susceptible to having their username/email revealed as existing. ## Details An attacker can easily enumerate and check users' existence using the recovery flow, as a clear message is shown when a user doesn't exist. Depending on configuration this can either be done by username, email, or both. The invalid and valid usernames should both show the same message and always send an email. Article for reference here: https://postmarkapp.com/guides/password-reset-email-best-practices#how-to-make-sure-your-password-reset-emails-are-secure ### For more information If you have any questions or comments about this advisory: - Email us at [[email protected]](mailto:[email protected])
### Withdrawn Advisory This advisory has been withdrawn due to an incorrect package mapping error. This link is maintained to preserve external references. ### Original Description ## Summary Using a recovery flow with an identification stage an attacker is able to determine if a username exists. ## Impact Only setups configured with a recovery flow are impacted by this. Anyone with a user account on a system with the recovery flow described above is susceptible to having their username/email revealed as existing. ## Details An attacker can easily enumerate and check users' existence using the recovery flow, as a clear message is shown when a user doesn't exist. Depending on configuration this can either be done by username, email, or both. The invalid and valid usernames should both show the same message and always send an email. Article for reference here: https://postmarkapp.com/guides/password-reset-email-best-practices#how-to-make-sure-your-password-reset-emails-are-secure ### For more information If you have any questions or comments about this advisory: - Email us at [[email protected]](mailto:[email protected])