This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
Summary
AI summaryFixed default credential misuse and an nginx location injection vulnerability.
Full changelog
What's Changed
Security
- Fixed a security issue related to default credentials in the configuration by @dmesad in https://github.com/wiredoor/wiredoor/pull/148
- Fixed an nginx location injection vulnerability by @dmesad in https://github.com/wiredoor/wiredoor/pull/149
- Updated OAuth2 Proxy to the latest supported version, including security and maintenance improvements by @dmesad in https://github.com/wiredoor/wiredoor/pull/150
Acknowledgements
Special thanks to @EQSTLab for responsibly reporting the security issues and helping improve Wiredoor's security.
Full Changelog: https://github.com/wiredoor/wiredoor/compare/v1.7.2...v1.7.3
Security Fixes
- Fixed default credential misuse in configuration (unspecified CVE).
- Fixed nginx location injection vulnerability (unspecified CVE).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About wiredoor
Self hosted ingress-as-a-service platform that allows you to expose applications and services running in private or local networks to the internet
Related context
Related tools
Beta — feedback welcome: [email protected]