THREAT OPS › Threat News › [GHSA] GHSA-rf68-8gjr-36q7 (low) — Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
[GHSA] GHSA-rf68-8gjr-36q7 (low) — Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
GHSA-rf68-8gjr-36q7 Severity: low CVE: None
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty
## Summary
Nezha v2.2.3 regresses the GHSA-9rc6-8cjv-rcvx host header injection fix for deployments where the new `dashboard_host` setting is empty. In that configuration, `/api/v1/oauth2/{provider}` again reflects the request `Host` header into the OAuth2 `redire
Indicators of compromise
- 3d74cd9431a48fa89c6489689eac82a872799ea0sha1
- https://idp.example.test/authorizeurl
- https://idp.example.test/tokenurl
- https://evil.attacker.test/api/v1/oauth2/callbackurl
Original source: https://github.com/advisories/GHSA-rf68-8gjr-36q7