User enumeration possible by SCRAM

Description

It is possible to test whether a given username exists on the system or not trivially using SCRAM. While it may be possible to determine this via other means (such as over the wire via XMPP queries for example) this presents an obvious and difficult to detect attack.

Environment

None

Activity

Show:
Fixed

Details

Assignee

Reporter

Fix versions

Priority

Created September 27, 2017 at 8:39 AM
Updated September 28, 2017 at 7:27 AM
Resolved September 28, 2017 at 7:27 AM

Flag notifications