Skip to content

Conversation

@wojcik91
Copy link
Contributor

@wojcik91 wojcik91 commented Sep 5, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: TOTP brute-forcing due to lack of rate limiting
ID: DG25-15
raport details: https://defguard.net/pentesting/
Adjust permissions on Unix socket to make it available only to users belonging to a specific group.
Update all relevant packages to setup the group and add the user to it as part of the install process.

Closes #1523

@wojcik91 wojcik91 self-assigned this Sep 5, 2025
@wojcik91 wojcik91 merged commit 937ad7e into release/1.5-alpha Sep 5, 2025
3 checks passed
@wojcik91 wojcik91 deleted the dg25-15_totp_brute_force_fix branch September 5, 2025 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants