Skip to content

Conversation

@j-chmielewski
Copy link
Contributor

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: [desktop_client] Unrestricted access to the local gRPC service
ID: DG25-27
report details: https://defguard.net/pentesting/

Implement gRPC communication over named pipes for windows.

Related issue: #551

@j-chmielewski j-chmielewski marked this pull request as ready for review October 28, 2025 13:38
@j-chmielewski j-chmielewski requested review from t-aleksander and wojcik91 and removed request for wojcik91 October 28, 2025 14:53
wojcik91
wojcik91 previously approved these changes Oct 29, 2025
@j-chmielewski j-chmielewski merged commit 96bc7e8 into dev Oct 29, 2025
3 checks passed
@j-chmielewski j-chmielewski deleted the fix-dg25-27 branch October 29, 2025 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants