Executive brief
fastify-reply-from is a Fastify plugin that forwards HTTP requests to a proxied backend service. A flaw allows attackers to craft specific URLs that bypass the configured URL prefix restriction, potentially accessing restricted backend resources that should be protected behind the proxy. This could expose sensitive endpoints that administrators intended to keep private.
Technical details
A path traversal/escape vulnerability exists in fastify-reply-from's URL routing logic that fails to properly validate and enforce the configured prefix boundary when forwarding requests to the proxied backend. An attacker can craft a malicious URL that escapes the intended prefix constraint—for example, if the proxy is configured to only allow access to /pub/ on the backend, an attacker can access /priv/ by bypassing the prefix check. The vulnerability requires no authentication and is remotely exploitable over the network. All versions prior to 4.0.2 are affected; patches are available in v4.0.2 and later.
Affected products
- Fastify fastify-reply-from all versions prior to 4.0.2
Timeline
- 2021-02-23: disclosed
- 2021-03-03: advisory
- 2021-03-02: patched: v4.0.2 and later include the fix