Executive brief
find-my-way is a Node.js HTTP router library used in web applications. The library accepts the Accept-Version header by default without proper cache key management, allowing attackers to poison web caches and cause denial of service when versioned routing is not in use. This could result in legitimate requests being denied or misdirected.
Technical details
find-my-way improperly handles the Accept-Version HTTP header as an unkeyed cache parameter, enabling HTTP cache poisoning attacks (CWE-444). The vulnerability affects versions before 2.2.5 and 3.0.0 through 3.0.4. When applications do not use versioned routes, the Accept-Version header can be manipulated to poison caches, causing availability issues. The attack requires network access but no authentication. The fix, released in versions 2.2.5 and 3.0.5, enables versioning on-demand rather than accepting it by default.
Affected products
- Matteo Collina find-my-way before 2.2.5, 3.0.0 to 3.0.4
Timeline
- 2020-11-09: disclosed