Serious vulnerabilities should be reported in private, using the contact details here. You can encrypt your message using my PGP key if you feel inclined to do so.
This page will be updated with any notices about security issues in BungeeGuard.
v1.2.0released which fixes a security issue in the BungeeGuard Spigot plugin.- The issue allowed malicious users to bypass BungeeGuard's authentication checks.
- All releases prior to
1.2are affected.
v1.4.0released which fixes a security issue in the BungeeGuard BungeeCord plugin.- An issue introduced in BungeeCord build 1756 caused the BungeeGuard token to be leaked to players using Minecraft 1.20.2 or higher via the LoginSuccess packet.
- This issue only affects BungeeGuard setups using BungeeCord, it does not affect Velocity proxies.
- Affected users are recommended to update to BungeeGuard
v1.4.0or later on their proxy, and rotate their BungeeGuard tokens.