This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+9 more
Affected surfaces
Summary
AI summaryGHSA-862h-v6cc-9757 and GHSA-2q37-6vxr-26jr fix critical authentication vulnerabilities in Websocket requests and SSH sessions.
Full changelog
Security fixes
GHSA-862h-v6cc-9757
In Websocket requests, a client could supply its own X-Wargate-Username header which would be appended to the upstream request, allowing the client to impersonate another user if the upstream relies on this header for authentication.
GHSA-2q37-6vxr-26jr
Incorrect authorization handling allowed an authenticated user to eavesdrop on another user's SSH session if they are able to obtain the session UUID.
Full Changelog: https://github.com/warp-tech/warpgate/compare/v0.25.5...v0.25.6
Security Fixes
- GHSA-862h-v6cc-9757 — prevents client‑supplied X-Wargate-Username header from impersonating users in Websocket requests
- GHSA-2q37-6vxr-26jr — fixes authorization handling to stop authenticated users from eavesdropping on other SSH sessions
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About warpgate
Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software
Related context
Beta — feedback welcome: [email protected]