GHSA-m492-gv72-xvxj: Kimai Password Reset Link Remains Valid After Password Change
The LoginLink signature used for password reset URLs covers only the user’s id — it does not include the password hash. After a user clicks a reset link and successfully changes their password, the same link remains valid for up to 2 additional uses within a 1-hour window. Anyone who intercepts or caches the original link can log in as the user even after the password has been changed.
References
Code Behaviors & Features
Detect and mitigate GHSA-m492-gv72-xvxj with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →