github warp-tech/warpgate v0.25.6

latest release: v0.26.0-beta.1
6 hours ago

Security fixes

GHSA-862h-v6cc-9757

In Websocket requests, a client could supply its own X-Wargate-Username header which would be appended to the upstream request, allowing the client to impersonate another user if the upstream relies on this header for authentication.

GHSA-2q37-6vxr-26jr

Incorrect authorization handling allowed an authenticated user to eavesdrop on another user's SSH session if they are able to obtain the session UUID.

Full Changelog: v0.25.5...v0.25.6

Don't miss a new warpgate release

NewReleases is sending notifications on new releases.