Skip to content

Fixes pentest issue DG25-13 from 2025-09-02#1530

Merged
wojcik91 merged 6 commits intorelease/1.5-alphafrom
dg25-13_disable_device_config
Sep 8, 2025
Merged

Fixes pentest issue DG25-13 from 2025-09-02#1530
wojcik91 merged 6 commits intorelease/1.5-alphafrom
dg25-13_disable_device_config

Conversation

@wojcik91
Copy link
Copy Markdown
Contributor

@wojcik91 wojcik91 commented Sep 8, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: User can see configuration even when this option is not visible in GUI
ID: DG25-13
raport details: https://defguard.net/pentesting/

Restrict access to device config endpoint if only_client_activation setting is enabled.

Closes #1526

@wojcik91 wojcik91 self-assigned this Sep 8, 2025
@wojcik91 wojcik91 merged commit 608e01f into release/1.5-alpha Sep 8, 2025
1 check passed
@wojcik91 wojcik91 deleted the dg25-13_disable_device_config branch September 8, 2025 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants