silverstripe/framework password encryption salt not updated
Low severity
GitHub Reviewed
Published
May 27, 2024
to the GitHub Advisory Database
•
Updated May 27, 2024
Package
Affected versions
>= 3.1.19-rc1, < 3.1.20
>= 3.2.4-rc1, < 3.2.5
>= 3.3.2-rc1, < 3.3.3
>= 3.4.0-rc1, < 3.4.1
Patched versions
3.1.20
3.2.5
3.3.3
3.4.1
Description
Published to the GitHub Advisory Database
May 27, 2024
Reviewed
May 27, 2024
Last updated
May 27, 2024
When a user changes their password, the internal salt used for hashing their password is not updated.
Although this is not considered a security vulnerability, this behaviour has been improved to ensure the salt is reset on change of password.
References