Releases: cloudfoundry/uaa
Releases · cloudfoundry/uaa
UAA 3.7.3 - Security Release (CVE-2016-6651)
This is a security release which addresses
UAA 2.7.4.9 - Security Release (CVE-2016-6651)
This is a security release which addresses
UAA 3.4.5 - Security Release (CVE-2016-6651)
This is a security release which addresses
UAA 3.3.0.6 - Security Release (CVE-2016-6651)
This is a security release which addresses CVE-2016-6651 Privilege Escalation in UAA
UAA 3.7.0 Release Notes
New Features
- Support token_format=opaque for refresh token
- Log the Audit Events in a separate log
- Add support for unlocking users
- User should be redirected to UAA to authenticate when accessing client app which does not support their origin IdP
- New Metrics for UAA - Auth Stats
- Allow overriding branding properties for each zone
Bug Fixes
- Token Signing Keys are improperly encoded
- UAA locations should always pass the logout redirect whitelist
- Going to UAA login page when already authenticated in UAA returns the 'UAA' home page regardless if the identity zone homeRedirect is configured
- LDAP Invitations failure on accept
- Zone Specific Reset Password and Create Account Links are not reflected in the Login UI
UAA 3.4.4 - Security Release (CVE-2016-6636 & CVE-2016-6637 )
This is a security release which addresses
UAA 3.3.0.5 - Security Release (CVE-2016-6636 & CVE-2016-6637 )
This is a security release which addresses
UAA 2.7.4.7 - Security Release (CVE-2016-6636 & CVE-2016-6637 )
This is a security release which addresses
UAA 2.7.4.6 - Security Release (CVE-2016-5016)
This is a security release which addresses CVE-2016-5016 UAA Accepts Expired Certificates
UAA 3.4.3 - Security Release (CVE-2016-5007)
This is a security release which addresses CVE-2016-5007 Spring Security / MVC Path Matching Inconsistency
This following dependencies have been updated
- Spring Security 4.1.1
- Spring Framework 4.3.1
- Spring Security Oauth 2.0.10
- Spring Security LDAP 2.1.0
- Spring Security SAML 1.0.2
- Apache Tomcat 8.0.36
- Apache Tomcat jdbc-pool 7.0.70