Password Reset Link Vulnerability in Enalean Tuleap
CVE-2018-17298
9.8CRITICAL
What is CVE-2018-17298?
A security flaw in Enalean Tuleap allows password reset links to remain valid even after a user successfully changes their password. This oversight can potentially expose users to unauthorized access, as anyone with access to these reset links can reset the passwords without detection. It’s crucial for systems dealing with sensitive information to ensure that all authentication and password processes invalidate outdated or unused links to maintain user security and privacy.