Security: unauthenticated mail amplification in the verify-email guards, and an account-existence oracle in handleBadDB. Upgrade to 5.7.0. See CHANGELOG 5.7.0.
Security: unauthenticated mail amplification in the verify-email guards, and an account-existence oracle in handleBadDB. Upgrade to 5.7.0. See CHANGELOG 5.7.0.
Security: unauthenticated mail amplification in the verify-email guards, and an account-existence oracle in handleBadDB. Upgrade to 5.7.0. See CHANGELOG 5.7.0.
Security: unauthenticated mail amplification in the verify-email guards, and an account-existence oracle in handleBadDB. Upgrade to 5.7.0. See CHANGELOG 5.7.0.
Security: account-enumeration oracles in resetPwd/updatePassword; 5.1.0 also fails to advance the email-change strike counter. Upgrade to 5.6.1. See CHANGELOG 5.1.1 and 5.2.0.
Security: account-enumeration oracles in resetPwd/updatePassword; 5.1.0 also fails to advance the email-change strike counter. Upgrade to 5.6.1. See CHANGELOG 5.1.1 and 5.2.0.
Critical: password reset can complete without the reset hash, and the reset token shares a field with the email-activation hash. Upgrade to 5.6.1. See CHANGELOG 5.0.3 and 5.1.0.
Critical: password reset can complete without the reset hash, and the reset token shares a field with the email-activation hash. Upgrade to 5.6.1. See CHANGELOG 5.0.3 and 5.1.0.
Critical: password reset can complete without the reset hash, and the reset token shares a field with the email-activation hash. Upgrade to 5.6.1. See CHANGELOG 5.0.3 and 5.1.0.
Critical: password reset can complete without the reset hash, and the reset token shares a field with the email-activation hash. Upgrade to 5.6.1. See CHANGELOG 5.0.3 and 5.1.0.
Critical: password reset can complete without the reset hash, and the reset token shares a field with the email-activation hash. Upgrade to 5.6.1. See CHANGELOG 5.0.3 and 5.1.0.