MEDIUM
GHSA-7fv8-6pp7-6h85
Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens
Quick fix
GHSA-7fv8-6pp7-6h85 — sulu/sulu: upgrade to the fixed version with the command below.
composer require sulu/sulu:^3.0.6Details
### Impact
The password reset tokenand API key generation uses a weak cryptographical hash algorithm.
### Patches
Fixed in 2.6.23 and 3.0.6 version.
### Workarounds
Patch the related `User.php` and `ResettingController.php` file in the SecurityBundle.
Are you affected?
Enter the version of the package you're using.