Junglewise Threat Intelligence

CVE-2022-31070: Finastra nestjs-proxy sensitive cookie exposure

CVE-2022-31070 · Severity: low · CVSS 3.1 · Published 2022-06-17

Vendors: npm.

Executive brief

@finastra/nestjs-proxy is a Node.js library that proxies HTTP requests to backend services. The library failed to block sensitive cookies (such as session cookies) by default when forwarding requests, potentially exposing authentication credentials to backend services that should not receive them. This could allow attackers to gain unauthorized access to backend systems if such cookies were leaked.

Technical details

The vulnerability is an information disclosure issue (CWE-200) in the nestjs-proxy library's cookie forwarding mechanism. The root cause is the library's default behavior of forwarding all cookies to backend services without filtering sensitive ones. An attacker with the ability to configure backend services or intercept proxied traffic could capture session cookies or other authentication credentials. The vulnerability affects all versions prior to 0.7.0, which introduced default cookie blocking with an optional allowlist for explicitly permitted cookies. The attack vector is local with high privileges and requires user interaction, limiting real-world exploit potential.

Affected products

  • Finastra @finastra/nestjs-proxy before 0.7.0
  • FFDC @ffdc/nestjs-proxy all versions (deprecated)

Timeline

  • 2022-06-17: disclosed: Advisory published
  • 2022-06-17: patched: @finastra/nestjs-proxy version 0.7.0 released with cookie blocking enabled by default

References

Related threats