-
Change Request
-
Resolution: Fixed
-
Critical
-
2.0.12, 2.0.13, 2.2.4, 2.2.5, 2.2.6, 2.3.3, 2.3.4, 2.3.5, 2.4.0
-
Sprint 69 (Oct 2020), Sprint 70 (Nov 2020)
-
3
Threat
The Web server allows form based authentication without disabling the AutoComplete feature for the password field.
Impact
The passwords entered by one user could be stored by the browser and retrieved for another user using the browser.
Solution
Contact the vendor to have the AutoComplete attribute disabled for the password field in all forms. The AutoComplete attribute should also be disabled for the user ID field.