Skip to content
This repository has been archived by the owner on Jan 4, 2024. It is now read-only.

ticket is not checked on any requests #35

Open
prettyClouds opened this issue Aug 9, 2023 · 0 comments
Open

ticket is not checked on any requests #35

prettyClouds opened this issue Aug 9, 2023 · 0 comments

Comments

@prettyClouds
Copy link

prettyClouds commented Aug 9, 2023

The ticket that is returned by authenticate when it is successful (UUID) is used by the client as a token. This code never checks the ticket, therefore any client can send data to this server and it will accept that data as 'real' without any validation.

I understand that this project is not actively worked on, but wanted to share this here in case anyone comes by and wants to use this. I would consider this a pretty big security vulnerability, and would not use this without fixing this issue.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant