Skip to content

Fixes pentest issue DG25-23 from 2025-09-02#1538

Merged
t-aleksander merged 4 commits intorelease/1.5-alphafrom
unauthorize-app
Sep 9, 2025
Merged

Fixes pentest issue DG25-23 from 2025-09-02#1538
t-aleksander merged 4 commits intorelease/1.5-alphafrom
unauthorize-app

Conversation

@t-aleksander
Copy link
Copy Markdown
Contributor

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

title: OpenID apps remain authorized even after the scope change
ID: DG25-23
raport details: https://defguard.net/pentesting/

Closes #1520

@t-aleksander t-aleksander merged commit 5093e8d into release/1.5-alpha Sep 9, 2025
1 check passed
@t-aleksander t-aleksander deleted the unauthorize-app branch September 9, 2025 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pentest - DG25-23: OpenID apps remain authorized even after the scope change

2 participants