Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signature Security Issue of RazorPay WebHook #244

Open
Aprameya123 opened this issue Mar 12, 2024 · 0 comments
Open

Signature Security Issue of RazorPay WebHook #244

Aprameya123 opened this issue Mar 12, 2024 · 0 comments

Comments

@Aprameya123
Copy link

The developer is able to access the signature of WebHook Request

Let me give a brief on why I think this is a security issue

Consider a software solution integrated with RazorPay

  • Customer of the software solution logs in to RazorPay sets up a webHook
  • During the processing of the webHook, developer can access the signature after encoding
  • This makes it so that the developer can manually send the WebHook Request which shouldn't be possible
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant