View Issue Details

IDProjectCategoryView StatusLast Update
0000615savapage-server[All Projects] Securitypublic2015-12-01 11:23
ReporterrijkrAssigned Torijkr 
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version0.9.9 
Target Version0.9.10Fixed in Version0.9.10 
Summary0000615: Prevent Account Enumeration and Guessable User Account
DescriptionIST: Some Web App authentication failure messages reveal user account existence.
SOLL: Give a neutral "authentication failed" message.
https://www.owasp.org/index.php/Testing_for_Account_Enumeration_and_Guessable_User_Account_(OTG-IDENT-004)
TagsNo tags attached.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2015-11-04 15:08 rijkr New Issue
2015-11-04 15:08 rijkr Status new => assigned
2015-11-04 15:08 rijkr Assigned To => rijkr
2015-11-04 15:11 rijkr Status assigned => resolved
2015-11-04 15:11 rijkr Fixed in Version => 0.9.10
2015-11-04 15:11 rijkr Resolution open => fixed
2015-12-01 11:23 rijkr Status resolved => closed