Skip to content

Re-use of password reset link

Moderate
b-meson published GHSA-gfjg-2w9g-vgj3 Aug 24, 2023

Package

No package listed

Affected versions

< 0.7.0

Patched versions

None

Description

A reset password link emailed to the user can be re-used within the hour after a password reset is requested for the user. An attacker with access to the user's email account or otherwise intercepts the link could successfully reset the user's account after the user's own reset.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits