ngrok Security Disclosure, May 2022
Blog post from Ngrok
Ngrok recently addressed a multi-tenancy bug in their dashboard's caching layer that inadvertently exposed some account data to fewer than 5% of its users, although no malicious activity has been reported. The bug allowed users to potentially view another's personal ngrok Authtoken, which, while limited in capability, could be used to initiate new tunnels. Important account information such as configuration data and sensitive credentials like passwords or payment data remained secure. Ngrok contacted affected users via email with remedial instructions to rotate their Authtoken. The issue stemmed from an optimization technique called 'request coalescing', which mistakenly combined requests for dashboard data from different users. After discovering the problem, ngrok fixed the bug and is now enhancing its systems to improve data handling and security measures, including rearchitecting the User Dashboard and increasing transparency through more detailed account activity events.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.