High
CVSS 7.5
Overview
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers ...
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
This vulnerability is rated 🟠 HIGH.
Recommended actions: