VDB
Sign up
MEDIUM

GHSA-7fv8-6pp7-6h85

Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens

Quick fix

GHSA-7fv8-6pp7-6h85 — sulu/sulu: upgrade to the fixed version with the command below.

composer require sulu/sulu:^3.0.6

Details

### Impact

The password reset tokenand API key generation uses a weak cryptographical hash algorithm.

### Patches

Fixed in 2.6.23 and 3.0.6 version.

### Workarounds

Patch the related `User.php` and `ResettingController.php` file in the SecurityBundle.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sulu/sulu
Introduced in: 3.0.0-alpha1Fixed in: 3.0.6
Fixcomposer require sulu/sulu:^3.0.6
Packagist/sulu/sulu
Introduced in: 0Fixed in: 2.6.23
Fixcomposer require sulu/sulu:^2.6.23

References