#35834: PasswordResetForm doesn't forward exceptions when email sending fails
-----------------------------------+--------------------------------------
     Reporter:  Olivier LEVILLAIN  |                    Owner:  (none)
         Type:  Bug                |                   Status:  closed
    Component:  contrib.auth       |                  Version:  5.1
     Severity:  Normal             |               Resolution:  wontfix
     Keywords:                     |             Triage Stage:  Unreviewed
    Has patch:  0                  |      Needs documentation:  0
  Needs tests:  0                  |  Patch needs improvement:  0
Easy pickings:  1                  |                    UI/UX:  0
-----------------------------------+--------------------------------------
Changes (by Tim Graham):

 * resolution:   => wontfix
 * status:  new => closed
 * type:  Uncategorized => Bug

Comment:

 When submitting an issue like this, you should check why the code was
 added. In this case, your proposal is to revert a security patch:

 In 8c35a0a903fd979e3262fe300ca084ffbfb300d6:

  > Fixed CVE-2024-45231 -- Avoided server error on password reset when
 email sending fails.
  >
  > On successful submission of a password reset request, an email is sent
 to the accounts known to the system. If sending this email fails (due to
 email backend misconfiguration, service provider outage, network issues,
 etc.), an attacker might exploit this by detecting which password
 resetrequests succeed and which ones generate a 500 error response.
-- 
Ticket URL: <https://code.djangoproject.com/ticket/35834#comment:1>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/01070192872c7196-20e30381-8371-4c93-beca-ca202d12e3d1-000000%40eu-central-1.amazonses.com.

Reply via email to