Skip to content

OAuth Insecure Redirect URI / Account Takeover

High
h44z published GHSA-2r2v-9pf8-6342 Jan 7, 2025

Package

gomod https://github.com/h44z/wg-portal (Go)

Affected versions

v2.0.0-alpha.1,v2.0.0-alpha.2

Patched versions

v2.0.0-alpha.3

Description

Impact

Users of WireGuard Portal v2 who have OAuth (or OIDC) authentication backends enabled can be affected by an Account Takeover vulnerability if they visit a malicious website.

Patches

The problem was fixed in the latest alpha release, v2.0.0-alpha.3. The docker images for the tag 'latest' built from the master branch also include the fix.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits