CVE-2019-16394: Canonical Ubuntu Linux

Medium severity, CVSS 5.3. EPSS: 7.3% chance of exploitation in the next 30 days.

SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Spip Spip: before 3.1.11 (fixed in 3.1.11); from 3.2.0, before 3.2.5 (fixed in 3.2.5)

Published 2019-09-17. Last modified 2026-06-17.