Problem/Motivation

An attacker could use the password reset process to identify email addresses with valid accounts.

Steps to reproduce

Run the password reset process with an email address known to have an account. The website responds with: "Further instructions have been sent to your email address." and response code 200. Run the password reset process with an email address known not to have an account. The process resopnds with: "This User was not found or invalid" and response code 400

Proposed resolution

Always give the same response regardless off the status of the account associated with the given email address.

Remaining tasks

Possibly give a different, equally uninformative response.

User interface changes

Responses given by the password reset process.

API changes

None

Data model changes

None

Comments

Adam Milward created an issue. See original summary.

taggartj’s picture

Assigned: Unassigned » taggartj
Status: Needs review » Reviewed & tested by the community

yes this is a good idea and yes I personally use this patch on my sites that use this module it will be in the next release as I missed this one in 8.1.8 thanks @Adam Milward

sittard’s picture

Any chance we could have a 8.1.9 release with this patch included? Thanks.

krzysztof domański’s picture

Status: Reviewed & tested by the community » Needs review
StatusFileSize
new1.86 KB
new1.94 KB
krzysztof domański’s picture

Version: 8.x-1.7 » 8.1.8
Assigned: taggartj » Unassigned
rajveergangwar’s picture

Hi,
rest_password-3223629-5.patch is showing your's email which should not as per the issue requirment.

https://www.rapid7.com/blog/post/2017/06/15/about-user-enumeration/

User enumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system. User enumeration is often a web application vulnerability, though it can also be found in any system that requires user authentication. Two of the most common areas where user enumeration occurs are in a site's login page and its ‘Forgot Password' functionality.

rest_password-3223629-4.patch Looks good for me.

rajveergangwar’s picture

Status: Needs review » Reviewed & tested by the community
glynster’s picture

Status: Reviewed & tested by the community » Fixed
glynster’s picture

Status: Fixed » Closed (fixed)