/plushcap/analysis/ngrok/ngrok-post-ngrok-security-disclosure-may-2022

ngrok Security Disclosure, May 2022

What's this blog post about?

Ngrok has disclosed a security vulnerability that affected less than 5% of its active users, causing data leakage between accounts when viewing the dashboard. The bug was caused by a caching layer issue and allowed personal Authtoken information to be viewed by another user. However, no malicious activity was detected, and all affected users have been contacted with remediation steps to rotate their Authtoken. Ngrok's engineering team has taken measures to improve log data handling, detect patterns, and respond effectively to similar incidents in the future.

Company
Ngrok

Date published
May 18, 2022

Author(s)
Alan Shreve

Word count
850

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.