Junglewise Threat Intelligence

CVE-2021-38384: Serverless Offline authorization bypass via trailing slash

CVE-2021-38384 · Severity: low · CVSS 3.1 · Published 2021-09-01

Vendors: npm.

Executive brief

Serverless Offline is a development tool that emulates AWS Lambda and API Gateway locally. A bug causes it to incorrectly reject requests with trailing slashes (returning HTTP 403) while AWS itself accepts them (returning HTTP 200), potentially leading developers to implement weaker access controls than intended. In production, attackers could exploit this discrepancy to bypass authorization checks that work on the local development system.

Technical details

Serverless Offline 8.0.0 and earlier incorrectly returns HTTP 403 for API requests to routes with trailing slashes (e.g., `/dashboard/`), while AWS API Gateway returns HTTP 200 for the same requests. This inconsistency is a form of authorization bypass via inconsistent behavior (CWE-863). The vulnerability stems from Serverless Offline's path matching logic not properly emulating AWS behavior. An attacker who discovers routes blocked in the development environment may be bypassed in production because AWS handles the same requests differently. This is particularly dangerous when custom authorizers rely on path-based access control, as developers may test against incorrect behavior during development and unknowingly deploy inadequate security logic.

Affected products

  • Serverless serverless-offline through 8.0.0

Timeline

  • 2021-08-10: disclosed: NVD publication date
  • 2021-09-01: advisory: GHSA advisory published
  • 2021-08-05: other: Issue reported on GitHub

References