Skip to content

Security issue: upgrade to pac4j v1.9.4 #516

@leleuj

Description

@leleuj

Unfortunately, we have a critical security issue in pac4j v1.9.2 and v1.9.3, if you use DbAuthenticator or MongoAuthenticator and the default password encoder NopPasswordEncoder.

You MUST upgrade to pac4j v1.9.4.

Hopefully, you haven't released any final version (only 1.0.0.CR8 is affected).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions