Junglewise Threat Intelligence

CVE-2021-32738: Stellar js-stellar-sdk auth bypass in SEP-10 challenge validation

CVE-2021-32738 · Severity: low · CVSS 3.1 · Published 2021-07-02

Vendors: npm.

Executive brief

The js-stellar-sdk library contains a flaw in its SEP-10 web authentication challenge validation function (Utils.readChallengeTx). Although the function claims to verify that the server has signed the challenge transaction, it fails to actually perform this signature verification. An attacker could bypass authentication by presenting a forged or unsigned challenge transaction, potentially gaining unauthorized access to applications relying on this function.</brief> <parameter name="technical_details">The vulnerability is a missing cryptographic signature verification in the Utils.readChallengeTx function used for SEP-10 Stellar Web Authentication. The function's documentation states it validates and verifies the server's signature on the challenge transaction, but the implementation does not actually perform server signature verification, resulting in an improper authentication (CWE-287) and insufficient signature verification (CWE-347) issue. Attack requires network access and is unauthenticated; an attacker can provide an unsigned or forged challenge transaction that the function will incorrectly accept as valid. Applications using alternative verification functions (Utils.verifyChallengeTxThreshold or Utils.verifyChallengeTxSigners) are unaffected. The vulnerability was fixed in version 8.2.3.

Affected products

  • Stellar js-stellar-sdk before 8.2.3

Timeline

  • 2021-07-02: disclosed
  • 2021-07-02: patched: Fixed in version 8.2.3

References