Project

General

Profile

Actions

Defect #6254

closed

Remove "Unknown user" notification on password request with non-existent email address

Added by Aron Rotteveel about 14 years ago. Updated about 1 year ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Accounts / authentication
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Currently, it is possible to retrieve valid e-mailaddreses from the system by simply trying to request a password for it. If the emailaddress is not valid, Redmine will show a notification stating this.

It would be better to have this form output a success message in every scenario in order to make e-mail harvesting harder.


Files

6254.patch (1.47 KB) 6254.patch Go MAEDA, 2022-07-21 11:49
6254-v2.patch (42.3 KB) 6254-v2.patch Go MAEDA, 2023-01-26 10:06

Related issues

Has duplicate Redmine - Defect #25144: Account Harvesting login issueClosed

Actions
Has duplicate Redmine - Defect #37517: User disclosure vulnerability via "Forgot password" functionalityClosed

Actions
Actions

Also available in: Atom PDF