GMS-2022-6726: Redwood is vulnerable to account takeover via dbAuth "forgot-password"
This is an API vulnerability in Redwood’s [dbAuth], specifically the dbAuth forgot password feature: - only projects with the dbAuth “forgot password” feature are affected - this vulnerability was introduced in v0.38.0
References
Detect and mitigate GMS-2022-6726 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →