Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Icon

If you would like to report an issue you believe is security related, you can do any of the following:

As always, sites are advised to use the latest stable release of any Grouper product. Refer to the Grouper Downloads page for information about our support and versioning policies. The Security Advisories page identifies the specific versions recommended at a given point in time

...

Date fixed

Affects versions

Patched for versions

Jira

Description and patch

24-Apr-20192.4v2_4_0_api_patch_42GRP-2110Use SSL context while making rabbitmq connection
20-Aug-20182.3 ui patch 44Patch for 2.3.0GRP-1875subject audits should only be seen by grouper admins
20-Aug-20182.3 api patch 109Patch for 2.3.0GRP-1876flash cache in groups can allow subjects to view (not read) objects with quick subsequent requests
20-Jul-20182.2 and 2.3Patch for 2.2.2 and 2.3.0GRP-1838xsrf problem with /UiV2Public.index
29-Nov-20151.4-2.2.2Patch for 2.2.2GRP-1227security issue with subject api init params
18-Nov-20152.2.0, 2.2.1, 2.2.2Patch for 2.2.2GRP-1222

xss vulnerability in tooltips in new UI

14-Sep-2013

2.1.5 and before


GRP-934

Grouper UI is susceptible to CSRF / XSRF Cross site request forgery

16-Aug-2013

1.41.51.62.02.1 (build 0,1,2,3,4)

1.4.21.5.31.6.32.0.32.1.4

GRP-928

Grouper UI allows unauthorized users to view the privileges of other subjects

2-Aug-2013

1.62.02.1 (build 0,1,2,3)

1.6.32.0.32.1.3

GRP-880

Deleting an attributeDef can cause incorrect membership deletes

1-Aug-2013

1.6, 2.0, 2.1 (build 0,1,2,3,4)

1.6.3, 2.0.3, 2.1.4

GRP-911 and GRP-924

Unauthorized users can delete attribute assignments

28-Jul-2013

1.41.51.62.02.1 (build 0,1,2,3,4)

1.4.21.5.31.6.32.0.32.1.4

GRP-923

WS getGrouperPrivilegesLite can return more data than the user should be able to see

22-Dec-2010

1.5 (build 0,1,2,3), 1.6 (build 0,1,2)

1.5.3, 1.6.2

GRP-519

A bug in the Grouper UI allows unauthorized users to view user audit logs by URL manipulation

...