Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-32591

#PT22227_6 Change password does not validated password strength

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Security

      Description

      Tested URL : https://pentest-2023.beta.nuxeocloud.com/nuxeo/api/v1/user/pentest-admin

      Severity : medium

      Criticality Justification
      Weak passwords could result in account compromise

      Steps To Reproduce

      Suggested Fix

      • Implement a strong password policy for all users. Consider implementing a stronger password policy for accounts with Administrative or other elevated privileges.
      • Cobalt recommends using the following criteria for a secure password policy:
      • Minimum Length: For standard users, require at least 12 characters. For Administrative users, consider requiring longer passwords, such as 15 or more characters.
      • Mixed Case*: Require passwords with a mix of upper and lowercase letters, to increase complexity.
      • Numbers*: Require passwords to include at least one number.
      • Special Characters*: Require at least one special character, such as !, ,, @, #, $, }}, or {{%.
      • Passphrases*: Do not set a maximum character limit. Encourage users to consider using passphrases, which can create longer, more memorable passwords with high entropy.
      • Password Topology*: Check the password candidates against commonly used weak passwords, such as \u201cpassword1\u201d, \u201cwinter2022\u201d, or passwords with the user\u2019s name, account name, or company name in them.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              santony Sooraj Antony
              Participants:
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: