Executive brief
TaffyDB is a JavaScript library that provides database features for web applications. An attacker can forge internal database indexes by adding properties to user input, allowing them to retrieve any data items from the database without proper authorization. The vulnerability exists because indexes use an easily-guessable format, completely bypassing query filtering logic.
Technical details
TaffyDB is vulnerable to internal property tampering (CWE-20, CWE-668) that allows unauthorized data access. The library uses an internal index (___id property) in a predictable format (e.g., T000002R000001) to track data items. An attacker can inject this ___id property into user-controlled query input; when the property is present, TaffyDB ignores all other query conditions and returns the indexed item directly. This affects all versions of both the deprecated 'taffy' package (through 2.6.2) and its successor 'taffydb' (through 2.7.3). The vulnerability is network-reachable if the application exposes TaffyDB queries over HTTP/REST, and no authentication is required to exploit it. Neither package is actively maintained, and no patch is available.
Affected products
- TaffyDB taffy all versions through 2.6.2
- TaffyDB taffydb all versions through 2.7.3
Timeline
- 2020-02-05: disclosed: Vulnerability disclosed to Snyk
- 2020-02-17: advisory: NVD published
- 2020-02-19: advisory: GitHub security advisory GHSA-mxhp-79qh-mcx6 published