{ "schema_version": "1.4.0", "id": "GHSA-gp48-6mgh-cg4v", "modified": "2022-05-17T04:45:44Z", "published": "2022-05-17T04:45:44Z", "aliases": [ "CVE-2014-2391" ], "details": "The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potentially useful password-pattern information by reading (1) a web-server access log, (2) a web-server Referer log, or (3) browser history that contains this string because of its presence in a GET request.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-2391" }, { "type": "WEB", "url": "http://www.securityfocus.com/archive/1/531762" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-04-24T05:06:00Z" } }