Junglewise Threat Intelligence

CVE-2022-24794: Auth0 express-openid-connect open redirect in requiresAuth middleware

CVE-2022-24794 · Severity: low · CVSS 3.1 · Published 2022-03-31

Vendors: Auth0, npm.

Executive brief

Auth0's express-openid-connect is a Node.js library that handles OpenID Connect authentication for Express web applications. When the requiresAuth middleware is applied to catch-all routes, an attacker can craft URLs with double slashes (e.g., //google.com) that bypass URL validation, causing authenticated users to be redirected to arbitrary external sites. This could be exploited for phishing attacks or credential theft.

Technical details

The vulnerability is an open redirect (CWE-601) in the requiresAuth middleware that fails to properly sanitize the original URL reported by Express before using it in redirects. When a user visits a URL like http://example.com//google.com with all routes protected by requiresAuth, the double-slash syntax causes the framework to treat the remainder as a domain rather than a path, and this unsanitized URL is used in the post-authentication redirect. No authentication is required to trigger the vulnerability—any unauthenticated visitor can craft the malicious URL. The fix, available in version 2.7.2 and later, properly sanitizes URL input before using it in redirects.

Affected products

  • Auth0 express-openid-connect <=2.7.1

Timeline

  • 2022-03-29: disclosed
  • 2022-03-31: patched: Version 2.7.2 released with fix
  • 2022-03-31: advisory

References

Related threats