You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: SECURITY.md
+6Lines changed: 6 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,3 +10,9 @@ This page will be updated with any notices about security issues in BungeeGuard.
10
10
*`v1.2.0` released which fixes a security issue in the BungeeGuard Spigot plugin.
11
11
* The issue allowed malicious users to bypass BungeeGuard's authentication checks.
12
12
* All releases prior to `1.2` are affected.
13
+
14
+
#### #002 - 2nd June 2025
15
+
*`v1.4.0` released which fixes a security issue in the BungeeGuard BungeeCord plugin.
16
+
* An issue introduced in BungeeCord build 1756 caused the BungeeGuard token to be leaked to players using Minecraft 1.20.2 or higher via the LoginSuccess packet.
17
+
* This issue only affects BungeeGuard setups using BungeeCord, it does not affect Velocity proxies.
18
+
* Affected users are recommended to update to BungeeGuard `v1.4.0` or later on their proxy, and rotate their BungeeGuard tokens.
0 commit comments