Executive brief
A vulnerability in the Fastify authentication library could allow attackers to perform unauthorized actions on behalf of users. By tricking a user's browser into using a pre-set security token, an attacker can bypass protections that normally prevent malicious websites from sending commands to the application. This could lead to unauthorized data changes or account modifications once a victim logs in.
Technical details
The @fastify/passport library fails to clear the session object upon user authentication. When used in conjunction with @fastify/csrf-protection, which utilizes the synchronizer token pattern, the '_csrf' attribute is preserved from the unauthenticated session to the authenticated one. An attacker can perform a 'cookie tossing' attack to fixate a known CSRF token in the victim's browser. Once the victim authenticates, the attacker can use the fixated token to perform Cross-Site Request Forgery (CSRF) attacks. The issue is resolved in versions 1.1.0 and 2.3.0 by introducing a default behavior that clears session attributes on login.
Affected products
- Fastify @fastify/passport <= 1.0.1, 2.0.0 <= 2.2.0
Timeline
- 2023-04-21: advisory: GitHub Security Advisory published
- 2023-04-21: patched: Fix committed to repository
References
- https://github.com/fastify/fastify-passport/security/advisories/GHSA-2ccf-ffrj-m4qw
- https://github.com/fastify/fastify-passport/commit/07c90feab9cba0dd4779e47cfb0717a7e2f01d3d
- https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html
- https://github.com/fastify/fastify-passport
- https://owasp.org/www-community/attacks/csrf