Account Enumeration Vulnerability in Talend Administration Center by Talend
CVE-2022-30332
5.3MEDIUM
What is CVE-2022-30332?
The Talend Administration Center has a flaw in its Forgot Password feature whereby different error messages are returned based on whether an email address is linked to an account. This discrepancy enables attackers to identify valid email addresses associated with user accounts by analyzing the response messages during multiple invalid reset request attempts. As a result, malicious actors can exploit this vulnerability to enumerate accounts, leading to potential unauthorized access or phishing attacks.
