Skip to content

fix: Only send password reset email to known, active addresses#5061

Merged
rjsparks merged 5 commits intoietf-tools:mainfrom
painless-security:jennifer/pw-reset
Jan 31, 2023
Merged

fix: Only send password reset email to known, active addresses#5061
rjsparks merged 5 commits intoietf-tools:mainfrom
painless-security:jennifer/pw-reset

Conversation

@jennifer-richards
Copy link
Copy Markdown
Member

Limits password reset to Users with a Person and at least one active address on file. Avoids the possibility of sending a password reset to a spoofed address as in CVE-2019-19844

@rjsparks rjsparks merged commit 98d7b15 into ietf-tools:main Jan 31, 2023
@jennifer-richards jennifer-richards deleted the jennifer/pw-reset branch January 31, 2023 20:43
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Feb 4, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants