-
v0.2.9 Stable
released this
2026-09-20 14:19:24 +00:00 | 2 commits to master since this releaseSecurity
- Org owners could mint recovery codes for co-members and take their accounts
- Org owners could create OAuth clients that skip the consent screen
- Team rename, delete and membership weren't bound to the org in the URL
- Org overview and branding were readable by non-members
- Handoff trusted any OAuth client, including self-registered ones
- SAML login handed the browser a 15-minute recovery link
- Invite and one-shot-reveal tokens were stored in plaintext
- CIMD client registration had no ceiling
X-Real-IPwas attacker-controlled on a short forwarded-for chain- The NSS resolver aborted sshd and sudo on an interior NUL
- The Linux client pinned a vulnerable rustls (RUSTSEC-2026-0285)
Changed
- Identity and session admin pages are operator-only;
?org=no longer admits owners - Org-created OAuth clients are limited to their own org's registered audiences
- New
[oauth.cimd].max_clientsandmax_clients_per_host
Builds, checksums and provenance: https://github.com/franzos/forseti/releases/tag/v0.2.9
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads