{"id":"GHSA-f28g-86hc-823q","summary":"Tokenizer vulnerable to client brute-force of token secrets","details":"### Impact\n\nAuthorized clients, having an `inject_processor` secret, could brute-force the secret token value by abusing the `fmt` parameter to the `Proxy-Tokenizer` header.\n\n### Patches\n\nThis was fixed in https://github.com/superfly/tokenizer/pull/8 and further mitigated in https://github.com/superfly/tokenizer/pull/9.","aliases":["GO-2023-1914"],"modified":"2024-05-20T21:54:03Z","published":"2023-07-13T19:56:19Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-13T19:56:19Z"},"references":[{"type":"WEB","url":"https://github.com/superfly/tokenizer/security/advisories/GHSA-f28g-86hc-823q"},{"type":"WEB","url":"https://github.com/superfly/tokenizer/pull/8"},{"type":"WEB","url":"https://github.com/superfly/tokenizer/pull/9"},{"type":"PACKAGE","url":"https://github.com/superfly/tokenizer"}],"affected":[{"package":{"name":"github.com/superfly/tokenizer","ecosystem":"Go","purl":"pkg:golang/github.com/superfly/tokenizer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-f28g-86hc-823q/GHSA-f28g-86hc-823q.json"}}],"schema_version":"1.9.0"}