Junglewise Threat Intelligence

CVE-2020-7764: find-my-way web cache poisoning via Accept-Version

CVE-2020-7764 · Severity: low · CVSS 3.1 · Published 2020-11-09

Technologies: Matteo Collina Find-My-Way.

Executive brief

find-my-way is a Node.js HTTP router library used in web applications. The library accepts the Accept-Version header by default without proper cache key management, allowing attackers to poison web caches and cause denial of service when versioned routing is not in use. This could result in legitimate requests being denied or misdirected.

Technical details

find-my-way improperly handles the Accept-Version HTTP header as an unkeyed cache parameter, enabling HTTP cache poisoning attacks (CWE-444). The vulnerability affects versions before 2.2.5 and 3.0.0 through 3.0.4. When applications do not use versioned routes, the Accept-Version header can be manipulated to poison caches, causing availability issues. The attack requires network access but no authentication. The fix, released in versions 2.2.5 and 3.0.5, enables versioning on-demand rather than accepting it by default.

Affected products

  • Matteo Collina find-my-way before 2.2.5, 3.0.0 to 3.0.4

Timeline

  • 2020-11-09: disclosed

References