Executive brief
Auth0's angular-jwt library is used to handle JSON Web Tokens (JWTs) in Angular applications, including domain filtering to control where authentication tokens are sent. The library incorrectly treats domain allowlist entries as regular expressions rather than literal strings, allowing attackers to bypass domain restrictions by registering domains that match regex patterns. An attacker could intercept JWT tokens intended for legitimate services and use them on attacker-controlled domains.
Technical details
The vulnerability is an input validation flaw (CWE-20) in angular-jwt versions before 0.1.10, where the whiteListedDomains configuration entries are evaluated as regex patterns instead of exact string matches. An attacker with knowledge of the allowlist configuration can craft a domain that matches the regex pattern—for example, if "whitelisted.example.com" is allowlisted, the dot separator is interpreted as a regex wildcard matching any character, so "whitelistedXexample.com" would bypass the filter. The attack requires network access and user interaction (the victim's browser must send a request to the attacker's domain). The fix, released in version 0.1.10, implements strict string-based domain comparison rather than regex matching.
Affected products
- Auth0 angular-jwt before 0.1.10
Timeline
- 2018-06-19: disclosed
- 2018-05-30: patched: Pull request merged; fix released in version 0.1.10