Skip to content

Conversation

@wojcik91
Copy link
Contributor

@wojcik91 wojcik91 commented Sep 8, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: User can bypass only_client_activation feature
ID: DG25-12
raport details: https://defguard.net/pentesting/

Restrict access to device management endpoints if only_client_activation setting is enabled.

Closes #1525

@wojcik91 wojcik91 self-assigned this Sep 8, 2025
@wojcik91 wojcik91 merged commit ce6f418 into release/1.5-alpha Sep 8, 2025
3 checks passed
@wojcik91 wojcik91 deleted the dg25-12_disable_device_creation branch September 8, 2025 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants