Version 6.5.2
Original release notes
- Update ldaptor dependency to address CVE-2025-20345, which could cause some configurations to output sensitive information during LDAP/AD password change operations to authproxy.log with debug-level logging enabled.
- We recommend customers who permit LDAP/AD password resets or changes for Duo Single Sign-On external Active Directory authentication sources or ldap_server_auto through the Duo Authentication Proxy upgrade to this release.