summaryrefslogtreecommitdiff
path: root/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml
diff options
context:
space:
mode:
Diffstat (limited to 'changelogs/unreleased/security-sarcila-fix-weak-session-management.yml')
-rw-r--r--changelogs/unreleased/security-sarcila-fix-weak-session-management.yml6
1 files changed, 6 insertions, 0 deletions
diff --git a/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml b/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml
new file mode 100644
index 00000000000..a37a3099519
--- /dev/null
+++ b/changelogs/unreleased/security-sarcila-fix-weak-session-management.yml
@@ -0,0 +1,6 @@
+---
+title: Fix weak session management by clearing password reset tokens after login (username/email)
+ are updated
+merge_request:
+author:
+type: security