- Issue created by @vikas_pal_1989
- 🇮🇳India vikas_pal_1989
This patch is destroying the session before the TFA module initiates a fresh session for reset password.
- 🇮🇳India vikas_pal_1989
Fixed the issue on edit profile page where it is asking for old password which should not be the case.
- Status changed to Closed: outdated
over 1 year ago 7:08pm 12 July 2023 - 🇺🇸United States cmlara
Closing as outdated on SA-CONTRIB-2023-030.
Please note in the future for security related issues they should be reported privately, though I'll concede this issue was a bit more complex in that it was publicly known and yet a maintainer tagged a stable release with it present.
NOTE: On January 29th 2023, as one of the reporters on SA-CONTRIB-2023-030 (I was not yet a maintainer) I requested the Drupal Security Team mark this issue private. When the security team and maintainer had not yet acted I used the April 13th update to ensure sites had a better chance to observe these known public faults and protect themselves.