Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGitLab Release Tools Bot <robert+release-tools@gitlab.com>2019-08-26 10:41:55 +0300
committerGitLab Release Tools Bot <robert+release-tools@gitlab.com>2019-08-26 10:41:55 +0300
commit29e1df85082b3403fc9f830307cd41e360420e1f (patch)
tree3b96d442b66b273583ea4d7780d29e3f367d74dc /changelogs/unreleased
parentb4642b84223e537b893bea83ef4c45664207eb27 (diff)
parent47d289b054a0e9a36f3da9ff503594e3f7511163 (diff)
Merge branch 'security-sarcila-fix-weak-session-management-12-0' into '12-0-stable'
Clear reset_password_tokens when login (email or username) change See merge request gitlab/gitlabhq!3348
Diffstat (limited to 'changelogs/unreleased')
-rw-r--r--changelogs/unreleased/security-sarcila-fix-weak-session-management.yml6
1 files changed, 6 insertions, 0 deletions
diff --git a/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml b/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml
new file mode 100644
index 00000000000..a37a3099519
--- /dev/null
+++ b/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml
@@ -0,0 +1,6 @@
+---
+title: Fix weak session management by clearing password reset tokens after login (username/email)
+ are updated
+merge_request:
+author:
+type: security