User enumeration is possible by performing a timing attack on the login or password reset pages with user credentials.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
3.5.0-rc1 | 3.5.5 |
silverstripe / framework
|
3.6.0-rc1 | 3.6.2 |