Executive brief
YMFE YApi is an API management platform. A vulnerability in how it generates security tokens allows an attacker to potentially predict and recreate login tokens for other users. This could lead to unauthorized access to the platform and sensitive API documentation.
Technical details
The yapi-vendor package (used by YApi) utilizes Node.js's Math.random() to generate the 'passsalt' string, which serves as the secret for signing JSON Web Tokens (JWT). Because Math.random() is a cryptographically insecure pseudo-random number generator (PRNG) based on the XorShift128+ algorithm, its internal state can be recovered by observing a sequence of outputs. An attacker can register multiple accounts to observe consecutive tokens, recover the PRNG state, and then brute-force or predict the signing secrets for other users' tokens. This vulnerability is fixed in version 1.9.3 by using a cryptographically secure random source.
Affected products
- YMFE yapi-vendor <= 1.9.2
Timeline
- 2020-11-18: disclosed: Report sent to maintainer
- 2021-03-01: advisory: NVD published date
- 2021-03-26: patched: GHSA published and fix confirmed in 1.9.3