When a user changes their password, the internal salt used for hashing their password is not updated.
Although this is not considered a security vulnerability, this behaviour has been improved to ensure the salt is reset on change of password.
| Software | From | Fixed in |
|---|---|---|
silverstripe / framework
|
3.1.19-rc1 | 3.1.20 |
silverstripe / framework
|
3.2.4-rc1 | 3.2.5 |
silverstripe / framework
|
3.3.2-rc1 | 3.3.3 |
silverstripe / framework
|
3.4.0-rc1 | 3.4.1 |