CVE-2016-3170: Infoleak
Email address can be matched to an account
Other sources
The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3170?
CVE-2016-3170 is classified as a moderately severe vulnerability that can lead to information disclosure.
How do I fix CVE-2016-3170?
To resolve CVE-2016-3170, update Drupal to versions 7.43 or later and 8.0.4 or later.
What are the affected versions for CVE-2016-3170?
CVE-2016-3170 affects Drupal versions 7.x before 7.43 and 8.x before 8.0.4.
What type of attack can CVE-2016-3170 be exploited for?
CVE-2016-3170 can be exploited by attackers to obtain sensitive username information.
Is CVE-2016-3170 specific to certain operating systems?
CVE-2016-3170 is specific to Drupal versions running on any compatible operating system, including Linux distributions like Debian.