VDB
Sign up
HIGH

GHSA-2r2v-9pf8-6342

WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover

Quick fix

GHSA-2r2v-9pf8-6342 — github.com/h44z/wg-portal: upgrade to the fixed version with the command below.

go get github.com/h44z/wg-portal@v2.0.0-alpha.3

Details

### Impact Users of WireGuard Portal v2 who have OAuth (or OIDC) authentication backends enabled can be affected by an Account Takeover vulnerability if they visit a malicious website.

### Patches The problem was fixed in the latest alpha release, v2.0.0-alpha.3. The [docker images](https://hub.docker.com/r/wgportal/wg-portal) for the tag 'latest' built from the master branch also include the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/h44z/wg-portal
Introduced in: 2.0.0-alpha.1Fixed in: 2.0.0-alpha.3
Fixgo get github.com/h44z/wg-portal@v2.0.0-alpha.3

References