—
RUSTSEC-2024-0010
Improper comparison of different-length signatures
Details
The `Webhook::verify` function incorrectly compared signatures of different lengths - the two signatures would only be compared up to the length of the shorter signature. This allowed an attacker to pass in `v1,` as the signature, which would always pass verification.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/svix
Introduced in:
0.0.0-0Fixed in: 1.17.0Upgrade svix to 1.17.0 or newer (ecosystem crates.io).