Users can deduce the content of the password fields by repeated call to LiveTableResults
and WikisLiveTableResultsMacros
.
The issue is applied on versions 14.7-rc-1, 13.4.4, and 13.10.9.
The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, and 13.10.9 and higher, or in version >= 3.2M3 by applying the patch manually on LiveTableResults
and WikisLiveTableResultsMacros
.
If you have any questions or comments about this advisory:
{ "nvd_published_at": "2023-03-02T19:15:00Z", "github_reviewed_at": "2023-03-03T22:47:49Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-200", "CWE-307" ] }