CVE-2017-5537: Infoleak
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/weblateto a version that resolves this vulnerability.Fixed in 2.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5537?
CVE-2017-5537 is considered a medium severity vulnerability due to the potential for user account enumeration.
How do I fix CVE-2017-5537?
To fix CVE-2017-5537, upgrade Weblate to version 2.10.1 or later.
What impact does CVE-2017-5537 have on user accounts?
CVE-2017-5537 allows attackers to determine if an email address is associated with a user account, leading to account enumeration.
In which versions of Weblate is CVE-2017-5537 present?
CVE-2017-5537 is present in Weblate versions prior to 2.10.1.
What type of vulnerability is CVE-2017-5537 classified as?
CVE-2017-5537 is classified as an information disclosure vulnerability.