• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.1
    • None
    • Core features
    • None

      Currently anyone can reset anyone else's password if they know the username. It would be better if Crowd mailed them a link that gave them the option to reset the password, and ignore otherwise.

            [CWD-86] Anyone can reset anyone elses password

            Monique Khairuliana (Inactive) made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 - restricted [ 1509314 ] New: JAC Bug Workflow v3 [ 3364000 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: Simplified Crowd Development Workflow v2 [ 1391100 ] New: Simplified Crowd Development Workflow v2 - restricted [ 1509314 ]
            Owen made changes -
            Workflow Original: Crowd Development Workflow v2 [ 273625 ] New: Simplified Crowd Development Workflow v2 [ 1391100 ]
            jawong.adm made changes -
            Workflow Original: JIRA Bug Workflow v2 [ 173325 ] New: Crowd Development Workflow v2 [ 273625 ]
            David O'Flynn [Atlassian] made changes -
            Fix Version/s New: 2.1 [ 14496 ]
            Resolution New: Fixed [ 1 ]
            Status Original: Open [ 1 ] New: Resolved [ 5 ]

            shihab added a comment -

            The solution to this problem is defined in the linked issue (CWD-1875).

            shihab added a comment - The solution to this problem is defined in the linked issue ( CWD-1875 ).
            shihab made changes -
            Link New: This issue duplicates CWD-1875 [ CWD-1875 ]

            How about captcha challenge?

            Aleksejs Mjaliks added a comment - How about captcha challenge?

            T Chan added a comment -

            This is a trivial denial-of-service attack. Knowing someone's username should not let you reset their password.

            Some sort of password-change-confirmation rate-limiting would be usful (e.g. it doesn't send more than one per day, reset when the user changes passwords).

            Secret questions a terrible idea, if only because they will almost certainly be used wrong.

            T Chan added a comment - This is a trivial denial-of-service attack. Knowing someone's username should not let you reset their password. Some sort of password-change-confirmation rate-limiting would be usful (e.g. it doesn't send more than one per day, reset when the user changes passwords). Secret questions a terrible idea, if only because they will almost certainly be used wrong.
            David O'Flynn [Atlassian] made changes -
            Link New: This issue is incorporated by CWD-1875 [ CWD-1875 ]

              justen.stepka@atlassian.com Justen Stepka [Atlassian]
              ssmith Steve Smith (Inactive)
              Affected customers:
              11 This affects my team
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: