{"id":"GHSA-f28g-86hc-823q","aliases":["GO-2023-1914"],"url":"https://o3.security/vulnerability/GHSA-f28g-86hc-823q","summary":"Tokenizer vulnerable to client brute-force of token secrets","details":"### Impact\n\nAuthorized clients, having an `inject_processor` secret, could brute-force the secret token value by abusing the `fmt` parameter to the `Proxy-Tokenizer` header.\n\n### Patches\n\nThis was fixed in https://github.com/superfly/tokenizer/pull/8 and further mitigated in https://github.com/superfly/tokenizer/pull/9.","published":"2023-07-13T19:56:19Z","modified":"2024-05-20T21:54:03Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/superfly/tokenizer","fixedVersion":"0.0.1"}],"fix":{"url":"https://github.com/superfly/tokenizer/pull/8","label":"superfly/tokenizer#8"},"references":[{"type":"WEB","url":"https://github.com/superfly/tokenizer/security/advisories/GHSA-f28g-86hc-823q"},{"type":"WEB","url":"https://github.com/superfly/tokenizer/pull/8"},{"type":"WEB","url":"https://github.com/superfly/tokenizer/pull/9"},{"type":"PACKAGE","url":"https://github.com/superfly/tokenizer"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-05-20T21:54:03Z"}}