Home / Companies / Ngrok / Blog / Post Details
Content Deep Dive

ngrok Security Disclosure, May 2022

Blog post from Ngrok

Post Details
Company
Date Published
Author
Alan Shreve
Word Count
830
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Ngrok recently addressed a multi-tenancy bug in their dashboard's caching layer that inadvertently exposed some account data to fewer than 5% of its users, although no malicious activity has been reported. The bug allowed users to potentially view another's personal ngrok Authtoken, which, while limited in capability, could be used to initiate new tunnels. Important account information such as configuration data and sensitive credentials like passwords or payment data remained secure. Ngrok contacted affected users via email with remedial instructions to rotate their Authtoken. The issue stemmed from an optimization technique called 'request coalescing', which mistakenly combined requests for dashboard data from different users. After discovering the problem, ngrok fixed the bug and is now enhancing its systems to improve data handling and security measures, including rearchitecting the User Dashboard and increasing transparency through more detailed account activity events.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.