Skip to content

Pentest - DG25-23: OpenID apps remain authorized even after the scope change #1520

@t-aleksander

Description

@t-aleksander

This issue is for vulnerability found by our security team during cyclical penetration testing of our solution.
Once the entire process is completed, a detailed report will be published, providing all interested parties with detailed information about the tests conducted and the issues that were reported on the soon to be published dedicated web page:

https://defguard.net/pentesting/

Please follow any issue you are interested, when the issue will be closed there will be linked pull request fixing the issue.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

Ready to release

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions