Pen testing found a security vulnerability in the Admin Tool that let someone extract a user’s password data if they gained access to an Admin account. To fix this, we had to remove:
The Connect and Disconnect menu option.
The IP address and username details from the application tray at the bottom of the screen.
We didn’t clearly explain this impact in the release notes, but we’re planning to update them with more details. After reviewing the confusion caused by removing the instance name, since it made it hard to tell which database the Admin Tool was connected to, we’ve reintroduced the instance name starting in Mosaic 22.2.4.0.
