Technical Tip: JAZZ-190: Reusable passphrase reset links
| Description | This article discusses JAZZ-190: Reusable passphrase reset links. |
| Scope | FortiDLP. |
| Solution | Release Date: 15th May, 2019
Overview: The passphrase reset links generated for Jazz operators (both credentials for newly provisioned operators and those generated via the operator management API) were found to be reusable within the expiry time of the token (48 hours by default).
Affected Products:
Unaffected Products:
Resolution: All Jazz Cloud customers have already been upgraded to the latest version and do not need to take any action. Passphrase reset links generated before upgrading will no longer be valid and must be regenerated.
Vulnerability Information: JAZZ-190 allows the reuse of a passphrase reset link within the expiry duration of the token (defaults to 48 hours). If the link was accessed by an attacker they would be able to reset the passphrase and take over the account, even after it had already been used. To take advantage of this vulnerability the attacker would require access to a password reset link within the expiry time. Expired links cannot be reused.
Acknowledgments: Issue found internally by Jazz Networks.
Disclosure Timeline:
|
