-
Bug
-
Resolution: Fixed
-
Medium
-
None
-
None
Currently anyone can reset anyone else's password if they know the username. It would be better if Crowd mailed them a link that gave them the option to reset the password, and ignore otherwise.
[CWD-86] Anyone can reset anyone elses password
Workflow | Original: Simplified Crowd Development Workflow v2 - restricted [ 1509314 ] | New: JAC Bug Workflow v3 [ 3364000 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: Simplified Crowd Development Workflow v2 [ 1391100 ] | New: Simplified Crowd Development Workflow v2 - restricted [ 1509314 ] |
Workflow | Original: Crowd Development Workflow v2 [ 273625 ] | New: Simplified Crowd Development Workflow v2 [ 1391100 ] |
Workflow | Original: JIRA Bug Workflow v2 [ 173325 ] | New: Crowd Development Workflow v2 [ 273625 ] |
Fix Version/s | New: 2.1 [ 14496 ] | |
Resolution | New: Fixed [ 1 ] | |
Status | Original: Open [ 1 ] | New: Resolved [ 5 ] |
The solution to this problem is defined in the linked issue (
CWD-1875).