GHSA-f28g-86hc-823q
Dashboard / Vulnerabilities / GHSA-f28g-86hc-823q
Summary: Tokenizer vulnerable to client brute-force of token secrets
Details: ### Impact Authorized clients, having an `inject_processor` secret, could brute-force the secret token value by abusing the `fmt` parameter to the `Proxy-Tokenizer` header. ### Patches This was fixed in https://github.com/superfly/tokenizer/pull/8 and further mitigated in https://github.com/superfly/tokenizer/pull/9.
References: https://github.com/superfly/tokenizer/security/advisories/GHSA-f28g-86hc-823q, https://github.com/superfly/tokenizer/pull/8, https://github.com/superfly/tokenizer/pull/9, https://github.com/superfly/tokenizer
Affected packages
Package
Name: github.com/superfly/tokenizer
Purl: pkg:golang/github.com/superfly/tokenizer
Affected ranges
Type: SEMVER
Events:
