Skip to content

Conversation

@filipslezaklab
Copy link
Contributor

@filipslezaklab filipslezaklab commented Sep 5, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: Broken access control - Unauthorized group listing and deletion
ID: DG25-9
raport details: https://defguard.net/pentesting/
Closes #1516

@filipslezaklab filipslezaklab self-assigned this Sep 5, 2025
@filipslezaklab filipslezaklab changed the title fix issue dg25-9 Fix dg25_9 vulnerability Sep 5, 2025
@filipslezaklab filipslezaklab changed the title Fix dg25_9 vulnerability Fixes pentest issue DG25-9 from 2025-09-02 Sep 5, 2025
moubctez
moubctez previously approved these changes Sep 5, 2025
@moubctez moubctez merged commit 588e602 into release/1.5-alpha Sep 5, 2025
3 checks passed
@moubctez moubctez deleted the dg25-9 branch September 5, 2025 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants