Uploaded image for project: 'Couchbase Server'
  1. Couchbase Server
  2. MB-28615

server SCRAM-SHA should not reveal that user doesn't exist

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 5.5.0
    • 5.5.0
    • memcached
    • None
    • Untriaged
    • Unknown

    Description

      Allows dictionary attack on users list

      Attachments

        For Gerrit Dashboard: MB-28615
        # Subject Branch Project Status CR V

        Activity

          People

            trond Trond Norbye
            artem Artem Stemkovski
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty