# Security issue on the ReactOS infrastructure

DevFeed: [Security issue on the ReactOS infrastructure](<https://devfeed.tech/articles/security-issue-on-the-reactos-infrastructure-33235.md>)

Original publisher: [Read original article](<https://reactos.org/project-news/security-issue-reactos-infrastructure-2015/>)

Published: 2015-01-21T00:00:00Z

Content type: news

Language: en

Sources: [Front Page on ReactOS Website](<https://devfeed.tech/sources/front-page-on-reactos-website.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [ReactOS](<https://devfeed.tech/topics/reactos.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [data](<https://devfeed.tech/topics/data.md>), [Users](<https://devfeed.tech/topics/users.md>), [email](<https://devfeed.tech/topics/email.md>)

Tags: [email](<https://devfeed.tech/tags/email.md>), [free](<https://devfeed.tech/tags/free.md>), [issue](<https://devfeed.tech/tags/issue.md>), [jira](<https://devfeed.tech/tags/jira.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [os](<https://devfeed.tech/tags/os.md>), [password](<https://devfeed.tech/tags/password.md>), [react](<https://devfeed.tech/tags/react.md>), [reactos](<https://devfeed.tech/tags/reactos.md>), [security](<https://devfeed.tech/tags/security.md>), [user](<https://devfeed.tech/tags/user.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [win32](<https://devfeed.tech/tags/win32.md>), [winapi](<https://devfeed.tech/tags/winapi.md>)

## AI overview

ReactOS reported discovering and fixing a vulnerability in its infrastructure that affected the main user database. The database may have exposed usernames, hashed passwords, and email addresses, although ReactOS said it had no evidence confirming or ruling out a leak and recommended that users change their passwords.

## Source excerpt

Dear all, On the 20th of January, we discovered a vulnerability affecting our infrastructure. This vulnerability has been immediately fixed after its discovery. Unfortunately, it was a vulnerability present for years on the infrastructure. This vulnerability was affecting our main users database. This means that our complete user database may have leaked, including user name, password (hashed) and email address. We do not have any evidence that the database actually leaked.