An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames.
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md