Skip to content

Conversation

@moubctez
Copy link
Contributor

@moubctez moubctez commented Sep 17, 2025

This pull request fixes vulnerability from penetration tests done by our security team on 2025-09-02:

Disable logging of sensitive data. Fixes DefGuard/defguard#1558

@moubctez moubctez changed the title Do not display sensitive data from protos Fixes pentest issue DG25-14 from 2025-09-02 Sep 17, 2025
@moubctez moubctez merged commit 3c0025e into dev Sep 17, 2025
3 checks passed
@moubctez moubctez deleted the block_sensitive_data_logging branch September 17, 2025 09:31
j-chmielewski added a commit that referenced this pull request Sep 24, 2025
* Fixes pentest issue DG25-16 from 2025-09-02 (#159)

* sanitize user agent to prevent html injection
* add tests

* Do not display sensitive data from protos (#167)

* use the same phone regex as backend does (#168)

* bump version to 1.5.1

* cargo update

---------

Co-authored-by: Maciek <19913370+wojcik91@users.noreply.github.com>
Co-authored-by: Adam <adam@defguard.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants