Junglewise Threat Intelligence

CVE-2022-2064: NocoDB insufficient session expiration

CVE-2022-2064 · Severity: low · CVSS 3.1 · Published 2022-06-14

Technologies: nocodb (npm). Vendors: NocoDB, npm.

Executive brief

NocoDB is an open-source Airtable alternative used to manage databases and collaborate on data. Sessions were not properly expiring after certain operations, allowing attackers with access to a browser after a user session ends to continue performing actions as that user until the browser session naturally expires. This could lead to unauthorized access to sensitive data and database modifications.

Technical details

NocoDB prior to version 0.91.9 suffered from insufficient session expiration (CWE-613) where user sessions were not properly invalidated after certain operations such as password changes. The vulnerability required prior authentication but could allow a threat actor with physical or adjacent access to an unlocked browser to continue performing API calls and database operations as the authenticated user. The fix (merged in PR #2338 and released in 0.91.9 on June 14, 2022) implements proper session termination, forcing users to re-authenticate after password changes and similar security-sensitive actions by dispatching a sign-out action and redirecting to the login page.

Affected products

  • NocoDB NocoDB prior to 0.91.9

Timeline

  • 2022-06-14: disclosed: Published in GitHub Advisory Database
  • 2022-06-14: patched: Fixed in version 0.91.9

References

Related threats