Skip to content

Releases: cloudfoundry/uaa-release

Updated to UAA Release 3.9.9

15 Mar 23:10
Compare
Choose a tag to compare

This release updates to UAA release 3.9.9

Updated to UAA Release 3.6.7

15 Mar 23:13
Compare
Choose a tag to compare

This release updates to UAA release 3.6.7

Updated to UAA Release 3.12.0 - Security Release (CVE-2017-4960)

28 Feb 01:50
Compare
Choose a tag to compare

This release updates to UAA release 3.12.0

This is a security release which addresses CVE-2017-4960: UAA OAuth DOS via lockout feature

This release re-introduces the JWT based Refresh Tokens. Refresh tokens are no longer opaque and revocable by default. This has been done to take care of the revocable_tokens table filling up with large deployments of UAA.

The format of the refresh token can now be set at an Identity Zone level via the API and can be boot strapped from the spec file for the default zone.

uaa.jwt.refresh.unique:
      description: "If true, uaa will only issue one refresh token per client_id/user_id combination"
      default: false
uaa.jwt.refresh.format:
      description: "The format for the refresh token. Allowed values are `jwt`, `opaque`"
      default: jwt

Updated to UAA Release 3.9.8 - Security Release (CVE-2017-4960)

15 Mar 23:14
Compare
Choose a tag to compare

This release updates to UAA release 3.9.8

This is a security release which addresses CVE-2017-4960: UAA OAuth DOS via lockout feature

Updated to UAA Release 3.11.0

15 Mar 23:16
Compare
Choose a tag to compare
Pre-release

Do-Not-Use

Updated to UAA Release 3.9.7

15 Mar 23:16
Compare
Choose a tag to compare
Pre-release

Do-Not-Use

Updated to UAA Release 3.9.6

15 Mar 23:17
Compare
Choose a tag to compare
Pre-release

Do-Not-Use

Updated to UAA release 3.9.5

15 Mar 23:18
Compare
Choose a tag to compare

This release updates to UAA release 3.9.5

Updated to UAA release 3.9.4

15 Mar 23:18
Compare
Choose a tag to compare

This release updates to UAA release 3.9.4

Updated to UAA release 3.6.6

15 Mar 23:20
Compare
Choose a tag to compare

This release updates to UAA release 3.6.6