#VU64572 Information Exposure Through an Error Message in Uyuni SUSE Manager - CVE-2022-31248
Published: June 22, 2022
Uyuni SUSE Manager
Uyuni Project
Description
The vulnerability allows a remote attacker to enumerate email addresses of registered users.
The vulnerability exists due to the application in /rhn/help/ForgotCredentials.do exposes information about pretense of an email address of the registered user within the application. A remote non-authenticated attacker can enumerate email addresses of application users.