Skip to content

subdomain Enumaration via side channel alerting security bug which is critical #201

@nguyenblacks

Description

@nguyenblacks

the AlgoraWeb.Endpoint contains a logic flaw in the canonical_host/2 function its pefroms a database lookup Algora.Accounts.get_user_by_handle/1 and triggers a cricitical security alert Algora.Activities.alert/2 based on weather ,e a subdomain matches a valid user handle

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions