Executive brief
express-jwt is a middleware library used to validate JSON Web Tokens (JWTs) in Express.js applications. When algorithms are not explicitly configured and the library is used with jwks-rsa, attackers can bypass authentication and authorization checks, potentially gaining unauthorized access to protected endpoints and user data.
Technical details
The vulnerability is an authorization bypass (CWE-285, CWE-863) caused by express-jwt versions ≤5.3.3 not enforcing the algorithms configuration parameter. When algorithms is omitted and the library is paired with jwks-rsa for secret retrieval, an attacker can craft malicious JWTs that bypass signature validation. The attack requires network access to the application and a valid user account or token (PR:L, UI:R). An attacker can read sensitive data and modify protected resources. The issue was fixed in version 6.0.0 by making algorithms a mandatory configuration parameter.
Affected products
- Auth0 express-jwt before 6.0.0
Timeline
- 2020-06-30: disclosed
- 2020-06-30: patched: Version 6.0.0 released