Email enumeration in password reset #5240
-
Hi, we've just finished building our first Statamic site for a client. The client has now had a security assessment run by an external infosec firm and one of their findings was the following:
This concerns the password reset functionality at I've seen that you explicitly mention "Username or email address enumeration" as non-qualifying vulnerabilities in your security policy. I guess my question would be why? It is a clear attack vector, even if the possible uses are limited. Best practice would seem to be serving generic messages instead of providing feedback on the (in)validity of submitted email addresses. Any guidance would be appreciated, thanks! I'm happy to open a corresponding issue if that's the best course of action. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
Sounds like a good feature request, I'd open it on the |
Beta Was this translation helpful? Give feedback.
Sounds like a good feature request, I'd open it on the
ideas
repo.