Junglewise Threat Intelligence

CVE-2020-11003: Oasis CSRF and DNS rebinding vulnerability

CVE-2020-11003 · Severity: low · CVSS 3.1 · Published 2020-04-16

Vendors: npm.

Executive brief

Oasis is a distributed social media platform. If a user visits a malicious website while running Oasis locally, an attacker can exploit CSRF and DNS rebinding techniques to read or write data to the application without authorization. There is no evidence of active exploitation in the wild.

Technical details

This vulnerability combines Cross-Site Request Forgery (CSRF) and DNS rebinding attacks against Oasis. The root cause is insufficient protection against CSRF in the application's request handling, allowing an attacker to craft malicious requests from a third-party site. DNS rebinding is leveraged to bypass same-origin policy protections by resolving a domain to localhost, where Oasis runs. An attacker must trick the user into visiting a malicious website while Oasis is running locally; no authentication bypass is required since the application is accessed locally. A successful attack allows reading or modifying data within the Oasis application. The vulnerability is patched in version 2.15.0 and later.

Affected products

  • Fraction Oasis before 2.15.0

Timeline

  • 2020-04-16: disclosed: GHSA-j438-45hc-vjhm published
  • 2020-04-16: patched: Fixed in version 2.15.0

References