Executive brief
tiny-csrf is a Node.js library used to protect web applications against cross-site request forgery (CSRF) attacks. Versions before 1.1.0 use weak encryption for CSRF tokens, allowing attackers to read and forge tokens, potentially leading to unauthorized actions on behalf of authenticated users.
Technical details
tiny-csrf versions prior to 1.1.0 implement weak encryption for CSRF token generation, making tokens readable by attackers (CWE-319: Cleartext Transmission of Sensitive Information). The vulnerable component fails to properly protect token confidentiality. The attack requires network access and user interaction (the victim must visit a malicious site while authenticated), but no authentication or special privileges are needed on the attacker's side. An attacker can extract CSRF tokens and forge valid requests on behalf of authenticated users. The vulnerability has been patched in version 1.1.0, released on 2022-10-07.
Affected products
- tiny-csrf tiny-csrf <1.1.0
Timeline
- 2022-10-07: disclosed
- 2022-10-07: patched: Fixed in version 1.1.0