summary refs log tree commit diff
path: root/changelog.d
diff options
context:
space:
mode:
authorDaniel Aloni <74783603+Danieloni1@users.noreply.github.com>2022-06-07 17:58:48 +0300
committerGitHub <noreply@github.com>2022-06-07 14:58:48 +0000
commitb5a3aecf18740fb699f871c8e1d110d847fea6d3 (patch)
tree2aa9222fac89627cb4e665cfe17ac8dcccf5aba6 /changelog.d
parentFix Synapse git info missing in version strings (#12973) (diff)
downloadsynapse-b5a3aecf18740fb699f871c8e1d110d847fea6d3.tar.xz
Return the same error message from `/login` when password is incorrect and when account doesn't exist. (#12738)
Diffstat (limited to 'changelog.d')
-rw-r--r--changelog.d/12738.misc1
1 files changed, 1 insertions, 0 deletions
diff --git a/changelog.d/12738.misc b/changelog.d/12738.misc
new file mode 100644
index 0000000000..8252223475
--- /dev/null
+++ b/changelog.d/12738.misc
@@ -0,0 +1 @@
+Report login failures due to unknown third party identifiers in the same way as failures due to invalid passwords. This prevents an attacker from using the error response to determine if the identifier exists. Contributed by Daniel Aloni.
\ No newline at end of file