CVE-2022-22120

    Dashboard / Vulnerabilities / CVE-2022-22120

    CVE-2022-22120

    Published: 10 Jan 2022Last Modified: 12 Aug 2026

    Summary: NocoDB - Observable Discrepancy in the password-reset feature

    Details: In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset feature. When requesting a password reset for a given email address, the application displays an error message when the email isn't registered within the system. This allows attackers to enumerate the registered users' email addresses.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- e3739302cde8b5e34a85d0be56954a869e682cea
    Fixed -f46e89b0

    Affected versions

    0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-22120 | CVE-DB