An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
{
"nvd_published_at": "2023-04-27T03:15:10Z",
"severity": "MODERATE",
"github_reviewed_at": "2023-04-27T17:09:01Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-209"
]
}