Skip to content

Conversation

@t-aleksander
Copy link
Contributor

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: OpenID apps do not respect scope
ID: DG25-22
raport details: https://defguard.net/pentesting/

Closes #1519

wojcik91
wojcik91 previously approved these changes Sep 9, 2025
@t-aleksander t-aleksander linked an issue Sep 9, 2025 that may be closed by this pull request
@t-aleksander t-aleksander merged commit 922075c into release/1.5-alpha Sep 9, 2025
3 of 4 checks passed
@t-aleksander t-aleksander deleted the fix-openid-scope branch September 9, 2025 10:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pentest - DG25-22: OpenID apps do not respect scope

3 participants