security: fix CVE 2022 46145 (#4140)

* add flow authentication requirement

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* add website for cve

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* add tests

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* flows: handle FlowNonApplicableException without policy result

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

* add release notes

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>

Signed-off-by: Jens Langhammer <jens.langhammer@beryju.org>
This commit is contained in:
Jens L
2022-12-02 16:14:25 +01:00
committed by GitHub
parent 860c85d012
commit db95dfe38d
30 changed files with 215 additions and 8 deletions

View File

@ -3802,6 +3802,10 @@ Changed response : **200 OK**
- sources/saml: set username field to name_id attribute
- web/common: disable API Drawer by default in user interface
## Fixed in 2022.10.2
- \*: fix CVE-2022-46145
## Upgrading
This release does not introduce any new requirements.

View File

@ -71,6 +71,10 @@ image:
- web/admin: fix error when importing duo devices
- web/admin: reset cookie_domain when setting non-domain forward auth
## Fixed in 2022.11.2
- \*: fix CVE-2022-46145
## API Changes
#### What's Changed