Executive brief
passport-cognito is an authentication library used to integrate Amazon Cognito login into web applications. A race condition in the library causes simultaneous users' authorization tokens (access, refresh, and ID tokens) to be improperly shared, allowing one user to perform actions on behalf of another user and access their account data.
Technical details
The vulnerability is an improper authorization issue (CWE-285) caused by inadequate variable scoping for authorization tokens (access token, refresh token, ID token) in the passport-cognito library. The race condition occurs when multiple users authenticate simultaneously, causing tokens to be mixed between user sessions. An attacker on the same platform during concurrent authentication attempts can intercept and use another user's tokens to impersonate them. The library was not patched at the time of advisory publication; no fix is currently available.
Affected products
- passport-cognito passport-cognito all versions
Timeline
- 2020-09-04: disclosed
- 2020-09-04: advisory