Problem/Motivation
An attacker could use the password reset process to identify email addresses with valid accounts.
Steps to reproduce
Run the password reset process with an email address known to have an account. The website responds with: "Further instructions have been sent to your email address." and response code 200. Run the password reset process with an email address known not to have an account. The process resopnds with: "This User was not found or invalid" and response code 400
Proposed resolution
Always give the same response regardless off the status of the account associated with the given email address.
Remaining tasks
Possibly give a different, equally uninformative response.
User interface changes
Responses given by the password reset process.
API changes
None
Data model changes
None
Comments
Comment #2
taggartj commentedyes this is a good idea and yes I personally use this patch on my sites that use this module it will be in the next release as I missed this one in 8.1.8 thanks @Adam Milward
Comment #3
sittard commentedAny chance we could have a 8.1.9 release with this patch included? Thanks.
Comment #4
krzysztof domańskiComment #5
krzysztof domańskiCopy message from Core #1521996: Password reset form reveals whether an email or username is in use.
Comment #6
krzysztof domańskiComment #7
rajveergangwarHi,
rest_password-3223629-5.patch is showing your's email which should not as per the issue requirment.
https://www.rapid7.com/blog/post/2017/06/15/about-user-enumeration/
User enumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system. User enumeration is often a web application vulnerability, though it can also be found in any system that requires user authentication. Two of the most common areas where user enumeration occurs are in a site's login page and its ‘Forgot Password' functionality.
rest_password-3223629-4.patch Looks good for me.
Comment #8
rajveergangwarComment #9
glynster commentedComment #10
glynster commented