Bug 2439622 (CVE-2019-25338)

Summary: CVE-2019-25338 dokuwiki: DokuWiki: Information disclosure through username enumeration in password reset
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in DokuWiki. This vulnerability, identified as a username enumeration, resides in the password reset functionality. A remote attacker can exploit this by submitting various usernames to the password reset endpoint. By observing the server's differing error responses, the attacker can determine which usernames correspond to valid user accounts, leading to information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2439689    
Bug Blocks:    

Description OSIDB Bzimport 2026-02-13 00:02:05 UTC
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user accounts. Attackers can submit different usernames to the password reset endpoint and distinguish between existing and non-existing accounts by analyzing the server's error response messages.