Skip to main content
Anthony_E
Staff
Staff
November 12, 2024

Technical Tip: JAZZ-190: Reusable passphrase reset links

  • November 12, 2024
  • 0 replies
  • 134 views
Description This article discusses JAZZ-190: Reusable passphrase reset links.
Scope FortiDLP.
Solution

Release Date:

15th May, 2019

 

Overview:

The passphrase reset links generated for Jazz operators (both credentials for newly provisioned operators and those generated via the operator management API) were found to be reusable within the expiry time of the token (48 hours by default).

 

Affected Products:

  • Only the Jazz Cloud since March 2019 is affected.

 

Unaffected Products:

  • On-premises installations are unaffected.

 

Resolution:

All Jazz Cloud customers have already been upgraded to the latest version and do not need to take any action. Passphrase reset links generated before upgrading will no longer be valid and must be regenerated.

 

Vulnerability Information:

JAZZ-190 allows the reuse of a passphrase reset link within the expiry duration of the token (defaults to 48 hours). If the link was accessed by an attacker they would be able to reset the passphrase and take over the account, even after it had already been used. To take advantage of this vulnerability the attacker would require access to a password reset link within the expiry time.

Expired links cannot be reused.

 

Acknowledgments:

Issue found internally by Jazz Networks.

 

Disclosure Timeline:

  • 11/05/2019 Issue found internally by Jazz.
  • 11/05/2019 Root cause established.
  • 11/05/2019 Fix identified.
  • 13/05/2019 Fix deployed to Jazz Cloud.
  • 15/05/2019 Vulnerability publicly disclosed.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!