Tokenizer vulnerable to client brute-force of token secrets
Moderate severity
GitHub Reviewed
Published
Jul 13, 2023
in
superfly/tokenizer
•
Updated May 20, 2024
Description
Published to the GitHub Advisory Database
Jul 13, 2023
Reviewed
Jul 13, 2023
Last updated
May 20, 2024
Impact
Authorized clients, having an
inject_processor
secret, could brute-force the secret token value by abusing thefmt
parameter to theProxy-Tokenizer
header.Patches
This was fixed in superfly/tokenizer#8 and further mitigated in superfly/tokenizer#9.
References