Password reset link not expiring after changing password in settings
Low
B
Basecamp
Submitted None
Team Summary
Official summary from Basecamp
@blackbibin reported password reset link not expiring when password was updated from an active session, by going to the Account's Login & Security setting. We were only expiring password reset links when the password was updated through a password reset request. Now we expire password reset links whenever a password is updated (besides regular time-based expiration).
Actions:
Reported by
zukito
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$250.00
Submitted
Weakness
Improper Authentication - Generic