CVE-2012-5055: Exposure of Sensitive Information to an Unauthorized Actor
(updated )
This package does not check the password if the user is not found, which makes the response delay shorter and might allow remote attackers to enumerate valid usernames via a series of login requests.
References
Detect and mitigate CVE-2012-5055 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →