Description
Allows dictionary attack on users list
Attachments
For Gerrit Dashboard: MB-28615 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
92538,5 | MB-28615: return generated salt if user doesn't exits in user database | master | ns_server | Status: MERGED | +2 | +1 |
92568,3 | MB-28615 pass scramsha_fallback_salt to memcached | master | ns_server | Status: MERGED | +2 | +1 |
92657,7 | MB-28615: SCRAM-SHA should not reveal that user doesn't exist | master | kv_engine | Status: MERGED | +2 | +1 |