MEDIUM
GHSA-f28g-86hc-823q
Tokenizer vulnerable to client brute-force of token secrets
Quick fix
GHSA-f28g-86hc-823q — github.com/superfly/tokenizer: upgrade to the fixed version with the command below.
go get github.com/superfly/tokenizer@v0.0.1Details
### Impact
Authorized clients, having an `inject_processor` secret, could brute-force the secret token value by abusing the `fmt` parameter to the `Proxy-Tokenizer` header.
### Patches
This was fixed in https://github.com/superfly/tokenizer/pull/8 and further mitigated in https://github.com/superfly/tokenizer/pull/9.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/superfly/tokenizer
Introduced in:
0Fixed in: 0.0.1Fix
go get github.com/superfly/tokenizer@v0.0.1