GHSA-rf68-8gjr-36q7: Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
Nezha v2.2.3 regresses the GHSA-9rc6-8cjv-rcvx host header injection fix for deployments where the new dashboard_host setting is empty. In that configuration, /api/v1/oauth2/{provider} again reflects the request Host header into the OAuth2 redirect_uri sent to the identity provider, even if install_host is configured.
References
Code Behaviors & Features
Detect and mitigate GHSA-rf68-8gjr-36q7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →