VDB
Sign up
MEDIUM

GHSA-f28g-86hc-823q

Tokenizer vulnerable to client brute-force of token secrets

Quick fix

GHSA-f28g-86hc-823q — github.com/superfly/tokenizer: upgrade to the fixed version with the command below.

go get github.com/superfly/tokenizer@v0.0.1

Details

### Impact

Authorized clients, having an `inject_processor` secret, could brute-force the secret token value by abusing the `fmt` parameter to the `Proxy-Tokenizer` header.

### Patches

This was fixed in https://github.com/superfly/tokenizer/pull/8 and further mitigated in https://github.com/superfly/tokenizer/pull/9.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/superfly/tokenizer
Introduced in: 0Fixed in: 0.0.1
Fixgo get github.com/superfly/tokenizer@v0.0.1

References