# "비밀번호 재설정" 대화상자의 이메일 열거 취약점

**URL:** https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449
**Category:** UX
**Created:** [8월 1, 2023, 7:37오전 UTC](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449 "2023-08-01T07:37:41Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [8월 1, 2023, 8:10오전 UTC](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449/4 "2023-08-01T08:10:59Z")

</div>

여러 자료를 살펴본 결과, 이 문제는 이전에 몇 번이나 발생했던 적이 있습니다. 제가 생각하기에 또 다른 중요한 점은 로그인 시도를 제한하는 레이트 리미팅이 있다는 것입니다:

> [@비밀번호 재설정 시 이메일 정보 유출 금지](https://meta.discourse.org/t/do-not-leak-emails-on-password-reset/176149/2?u=jammydodger):
>
> This is not a bug. We have a site setting called hide email address taken that prevents it. There are also rate-limits on sign in so it’s not particularly easy to brute force large numbers of email addresses.

---

_[View the full topic](https://meta.discourse.org/t/email-enumeration-vulnerability-on-password-reset-dialogue/273449)._
