Password reset can be abused to block accounts (OD-1615)
Robin Shen opened 2 years ago

From user:

Looks like the reset password feature of OneDev can be abused to lock users out of their accounts. It resets the user's password immediately, instead of creating a temporary access token that can only be used to reset the password, keeping the existing password valid until this is done.

What if I temporarily don't have access to my email account, if the email address in my profile is no longer valid, if some aggressive spam filter is blocking the reset email, and so on? Somebody can lock me out and require admin or shell access to fix that.

  • Robin Shen changed fields 2 years ago
    Name Previous Value Current Value
    Type
    Bug
    Security Vulnerability
  • Robin Shen changed fields 2 years ago
    Name Previous Value Current Value
    Priority
    Major
    Normal
  • Robin Shen changed fields 2 years ago
    Name Previous Value Current Value
    Priority
    Normal
    Major
  • Robin Shen changed title 2 years ago
    Previous Value Current Value
    Password reset can be used to block account from signing in by malicious users
    Password reset can be used to block account by malicious users
  • Robin Shen changed title 2 years ago
    Previous Value Current Value
    Password reset can be used to block account by malicious users
    Password reset can be abused to block accounts
  • OneDev changed state to 'Closed' 2 years ago
    Previous Value Current Value
    Open
    Closed
  • OneDev commented 2 years ago

    State changed as code fixing the issue is committed (d1de32b6)

  • OneDev changed state to 'Released' 2 years ago
    Previous Value Current Value
    Closed
    Released
  • OneDev commented 2 years ago

    State changed as build #4241 is successful

issue 1/1
Type
Security Vulnerability
Priority
Major
Assignee
Labels
No labels
Issue Votes (0)
Watchers (2)
Reference
OD-1615
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover