Executive brief
Strapi is an open-source headless CMS widely used to manage and serve content to applications. When Strapi is configured to use AWS Cognito for user authentication, the system fails to validate the cryptographic signatures of authentication tokens returned by Cognito. An attacker can craft forged tokens that claim to be any user without needing legitimate credentials, leading to unauthorized account takeover and access to sensitive content or administrative functions.
Technical details
The vulnerability is an authentication bypass in the OAuth/OIDC token validation logic within Strapi's users-permissions plugin, specifically when AWS Cognito is used as the identity provider. The affected code in the providers-registry.js service failed to verify the JWT signature of ID tokens returned during the OAuth flow, permitting tokens signed with the 'None' algorithm (an RFC-defined but dangerous algorithm option) to be accepted as valid. An unauthenticated remote attacker can construct a malicious JWT claiming any user identity and submit it during the OAuth callback phase to gain authenticated access without valid credentials. The fix, released in version 4.6.0, implements proper JWT signature verification using AWS's published key sets (JWKS). Patches are available in commits 46f8f98, 8bbbd73, and eeab43b on the Strapi repository.
Affected products
- Strapi @strapi/plugin-users-permissions 3.2.1 through 4.5.9
Timeline
- 2023-04-19: disclosed
- 2023-04-24: patched: Fix released in Strapi 4.6.0
References
- https://github.com/strapi/strapi/commit/46f8f98378338f18b5c6139d0157a8f71bf4de83
- https://github.com/strapi/strapi/commit/8bbbd7383a20bb7cb163c8b462baffee559e994f
- https://github.com/strapi/strapi/commit/eeab43b57707d7ef275076d27be6eabc72bd71a7
- https://github.com/strapi/strapi
- https://github.com/strapi/strapi/blob/v4.5.6/packages/plugins/users-permissions/server/services/providers-registry.js
- https://github.com/strapi/strapi/releases