Executive brief
NextAuth's Upstash Redis Adapter is used to manage user sessions and email-based authentication in web applications. The adapter failed to properly validate email verification tokens, allowing an attacker who knows a victim's email address to sign in as that user if they can guess or obtain the verification token. This bypasses the intended email-based authentication flow and compromises account security.
Technical details
The vulnerability is an authentication bypass (CWE-287/CWE-285) in the Upstash Redis Adapter's email verification flow. The vulnerable code checked only the email identifier against stored verification tokens but did not validate that the provided token matched the stored token value. An unauthenticated attacker with network access to the application can exploit this by providing a known email address and a guessed or obtained verification token. Precondition: the application must use the Email Provider with the Upstash Redis Adapter for authentication. Successful exploitation allows account takeover with high impact on confidentiality and integrity. The vulnerability was patched in version 3.0.2 with a commit that adds proper token validation alongside email identifier checking.
Affected products
- NextAuth @next-auth/upstash-redis-adapter before 3.0.2
Timeline
- 2022-09-28: disclosed: CVE published
- 2022-09-30: disclosed: GHSA advisory published
- 2022-09-28: patched: Fix committed (v3.0.2)