[D7] Username disclosure in /user/password

Created on 26 August 2023, over 1 year ago
Updated 1 December 2023, about 1 year ago

Problem/Motivation

This is a backport of 🐛 User email disclosure in /user/password Fixed . We probably want to backport this security improvement.

Steps to reproduce

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

Release notes snippet

🐛 Bug report
Status

Fixed

Version

7.0 ⚰️

Component
User module 

Last updated 7 days ago

Created by

🇸🇰Slovakia poker10

Live updates comments and jobs are added and updated live.
  • Security improvements

    It makes Drupal less vulnerable to abuse or misuse. Note, this is the preferred tag, though the Security tag has a large body of issues tagged to it. Do NOT publicly disclose security vulnerabilities; contact the security team instead. Anyone (whether security team or not) can apply this tag to security improvements that do not directly present a vulnerability e.g. hardening an API to add filtering to reduce a common mistake in contributed modules.

Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024