Minimize reset password SMS expiracy duration [Updated in Security Center 1.3]

  • Release version: Washingtondc
  • Updated February 1, 2024
  • 1 minute to read
  • Control the number of minutes remaining before the SMS code expires.

    The password_reset.sms.expiry property represents the number of minutes remaining before the SMS code expires.

    More information

    Attribute Description
    Configuration name password_reset.sms.expiry
    Configuration type System Properties (/sys_properties_list.do)
    Data type integer
    Recommended value 5
    Default value 5
    Category Authentication
    Security risk
    • Severity score: 5.6
    • CVSS score: Medium
    • Security risk details: If this property is not set to the recommended value of 5 or less, the chances of a bad actor guessing and using the SMS code to reset the password increases.
    Dependencies and prerequisites None