GHSA-f28g-86hc-823q: Tokenizer vulnerable to client brute-force of token secrets
(updated )
Authorized clients, having an inject_processor
secret, could brute-force the secret token value by abusing the fmt
parameter to the Proxy-Tokenizer
header.
References
Detect and mitigate GHSA-f28g-86hc-823q with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →