HIGH
GHSA-2r2v-9pf8-6342
WireGuard Portal v2 Vulnerable to OAuth Insecure Redirect URI / Account Takeover
Quick fix
GHSA-2r2v-9pf8-6342 — github.com/h44z/wg-portal: upgrade to the fixed version with the command below.
go get github.com/h44z/wg-portal@v2.0.0-alpha.3Details
### Impact Users of WireGuard Portal v2 who have OAuth (or OIDC) authentication backends enabled can be affected by an Account Takeover vulnerability if they visit a malicious website.
### Patches The problem was fixed in the latest alpha release, v2.0.0-alpha.3. The [docker images](https://hub.docker.com/r/wgportal/wg-portal) for the tag 'latest' built from the master branch also include the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/h44z/wg-portal
Introduced in:
2.0.0-alpha.1Fixed in: 2.0.0-alpha.3Fix
go get github.com/h44z/wg-portal@v2.0.0-alpha.3