This bug can be trivially used to knock over any existing production deployment of Horizon that doesn't use cookie-based sessions.
There is no amplification, but I suspect I can break most production deployments to the point that fixing requires manual intervention in less than 30 minutes. I'd prefer not to make that public without also providing a fix.
I'd argue we should probably treat that as A or B1.
This bug can be trivially used to knock over any existing production deployment of Horizon that doesn't use cookie-based sessions.
There is no amplification, but I suspect I can break most production deployments to the point that fixing requires manual intervention in less than 30 minutes. I'd prefer not to make that public without also providing a fix.
I'd argue we should probably treat that as A or B1.