Junglewise Threat Intelligence

CVE-2020-15084: Auth0 express-jwt authorization bypass

CVE-2020-15084 · Severity: low · CVSS 3.1 · Published 2020-06-30

Vendors: Auth0, npm.

Executive brief

express-jwt is a middleware library used to validate JSON Web Tokens (JWTs) in Express.js applications. When algorithms are not explicitly configured and the library is used with jwks-rsa, attackers can bypass authentication and authorization checks, potentially gaining unauthorized access to protected endpoints and user data.

Technical details

The vulnerability is an authorization bypass (CWE-285, CWE-863) caused by express-jwt versions ≤5.3.3 not enforcing the algorithms configuration parameter. When algorithms is omitted and the library is paired with jwks-rsa for secret retrieval, an attacker can craft malicious JWTs that bypass signature validation. The attack requires network access to the application and a valid user account or token (PR:L, UI:R). An attacker can read sensitive data and modify protected resources. The issue was fixed in version 6.0.0 by making algorithms a mandatory configuration parameter.

Affected products

  • Auth0 express-jwt before 6.0.0

Timeline

  • 2020-06-30: disclosed
  • 2020-06-30: patched: Version 6.0.0 released

References