Executive brief
A vulnerability in the Connect middleware for Node.js could allow attackers to execute malicious scripts in a user's browser. This occurs when the application uses the 'methodOverride' feature to process web requests. If an attacker sends a specially crafted request, the server may reflect that script back to the user in an error page, potentially leading to unauthorized actions or data theft from the user's session.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the 'methodOverride' middleware of the Connect framework. The middleware allows an HTTP POST request to override the request method using the '_method' parameter or 'x-http-method-override' header. Because the input provided to these fields was not validated or sanitized, an attacker could inject a script as the method name. When the application fails to find a matching route for the malicious method, it returns a 404 error page that includes the unescaped method string in the response body (e.g., 'Cannot [method] [url]'). This allows for the execution of arbitrary JavaScript in the context of the victim's browser session. The issue was addressed in version 2.8.1 by escaping the output and whitelisting supported methods.
Affected products
- Sencha Labs connect < 2.8.1
Timeline
- 2013-06-27: disclosed: Issue reported on GitHub repository
- 2013-07-24: patched: Fixes committed to repository
- 2019-12-11: advisory: NVD published CVE-2013-7370
- 2020-08-31: advisory: GitHub Advisory published
References
- https://github.com/senchalabs/connect/issues/831
- https://github.com/senchalabs/connect/commit/126187c4e12162e231b87350740045e5bb06e93a
- https://github.com/senchalabs/connect/commit/277e5aad6a95d00f55571a9a0e11f2fa190d8135
- https://access.redhat.com/security/cve/cve-2013-7370
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7370
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-7370