This release includes 1 security fix for security teams reviewing exposed deployments.
Published 20d
Offensive & Pentesting
β No known CVEs patched
This release patches 1 known CVE
Topics
aws
azure
cis-benchmark
cloud
cloudsecurity
compliance
+12 more
cspm
security
forensics
gcp
gdpr
hardening
iam
multi-cloud
python
security-audit
security-hardening
security-tools
Affected surfaces
auth
rbac
Summary
AI summaryUpdates π Fixed, https://github.com/prowler-cloud/prowler/pull/11752, and π Security across a mixed release.
Full changelog
UI
π Fixed
- Invitation callback paths are now preserved when invited users continue with Google, GitHub, or SAML authentication (#11752)
API
π Fixed
- Attack Paths: Scan rows now have database defaults for
is_migratedandsink_backendsoscan-perform-scheduledinserts survive deploy skew (#11826) - Invited users now keep their invitation context when completing authentication with Google, GitHub, or SAML, so the invitation is accepted during login (#11752)
π Security
- User profile updates now allow users to update their own account while requiring user-management permissions to update other users in the same tenant (#11792)
SDK
π Fixed
KeyError: 'MANUAL'crash while rendering the compliance summary table (e.g. CIS Microsoft 365) when a framework has manual, checks-less requirements with a Level 1/Level 2 profile;MANUALfindings are now skipped in the PASS/FAIL section tally instead of raising (#11822)
Security Fixes
- User profile updates enforce userβmanagement permission checks, preventing unauthorized modifications of other users
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Prowler
Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.
Beta — feedback welcome: [email protected]