Disabled users with external authentication retain access to Rudder
Package
rudder-server
(rudder)
Affected versions
7.3.13
8.0.7
8.1.0
Patched versions
7.3.14
8.0.8
8.1.1
Impact
Users which are disabled and provisioned by LDAP/OAuth2/OIDC could still login for an indefinite period of time.
Patches
Workarounds
Don't use the disable feature but remove the account to prevent access to Rudder.
References