GMS-2022-6935: Plaintext storage of password after a reset in xwiki-platform-security-authentication-default
We discovered that when the reset a forgotten password feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki 13.1RC1 and next versions.
References
Detect and mitigate GMS-2022-6935 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →