Skip to content

Reset Password not protected against well-timed CSRF

Low
mark-netalico published GHSA-r3c9-9j5q-pwv4 Jan 26, 2023

Package

No package listed

Affected versions

<= 19.4.21, <= 20.0.18

Patched versions

None

Description

Impact

Password reset form is vulnerable to CSRF between time reset password link is clicked and user submits new password.

Patches

PR forthcoming

Workarounds

None

Severity

Low

CVE ID

CVE-2021-21395

Weaknesses

No CWEs