Skip to content

Conversation

@disconnect3d
Copy link
Contributor

TL;DR: The base64url string is of len 9 but we compared only its first 6 bytes.

This was found with a "cstrnfinder" research and I haven't tested this change (more info https://twitter.com/disconnect3d_pl/status/1339757359896408065). Close this PR if this change is incorrect.

TL;DR: The `base64url` string is of len 9 but we compared only its first 6 bytes.

This was found with a "cstrnfinder" research and I haven't tested this change (more info https://twitter.com/disconnect3d_pl/status/1339757359896408065). Close this PR if this change is incorrect.
@lexborisov
Copy link
Contributor

@disconnect3d

Thanks for the patch!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants