Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Advisories noted for "All" versions should be reviewed by all deployers for relevancy to their deployment. Typically this indicates that an advisory is at least partly discussing issues that go beyond the scope of what the Grouper software can actually remediate and may affect the deployment as a whole. It does not in general refer to unfixed vulnerabilities in the Grouper software itself.

...

 Security Issues

Date fixed

Affects versions

Patched for versions

Jira

Description and patch

29-Nov-20151.4-2.2.2Patch for 2.2.2GRP-1227security issue with subject api init params
18-Nov-20152.2.0, 2.2.1, 2.2.2Patch for 2.2.2GRP-1222

xss vulnerability in tooltips in new UI

14-Sep-2013

2.1.5 and before

 

GRP-934

Grouper UI is susceptible to CSRF / XSRF Cross site request forgery

16-Aug-2013

1.41.51.62.02.1 (build 0,1,2,3,4)

1.4.21.5.31.6.32.0.32.1.4

GRP-928

Grouper UI allows unauthorized users to view the privileges of other subjects

2-Aug-2013

1.62.02.1 (build 0,1,2,3)

1.6.32.0.32.1.3

GRP-880

Deleting an attributeDef can cause incorrect membership deletes

1-Aug-2013

1.6, 2.0, 2.1 (build 0,1,2,3,4)

1.6.3, 2.0.3, 2.1.4

GRP-911 and GRP-924

Unauthorized users can delete attribute assignments

28-Jul-2013

1.41.51.62.02.1 (build 0,1,2,3,4)

1.4.21.5.31.6.32.0.32.1.4

GRP-923

WS getGrouperPrivilegesLite can return more data than the user should be able to see

22-Dec-2010

1.5 (build 0,1,2,3), 1.6 (build 0,1,2)

1.5.3, 1.6.2

GRP-519

A bug in the Grouper UI allows unauthorized users to view user audit logs by URL manipulation


Children Display

See Also

Grouper Versioning and Support Policy for earlier Grouper releases.

...