Junglewise Threat Intelligence

CVE-2023-29020: Fastify @fastify/passport CSRF token fixation

CVE-2023-29020 · Severity: low · CVSS 3.1 · Published 2023-04-21

Vendors: Fastify.

Executive brief

A vulnerability in the Fastify authentication library could allow attackers to perform unauthorized actions on behalf of users. By tricking a user's browser into using a pre-set security token, an attacker can bypass protections that normally prevent malicious websites from sending commands to the application. This could lead to unauthorized data changes or account modifications once a victim logs in.

Technical details

The @fastify/passport library fails to clear the session object upon user authentication. When used in conjunction with @fastify/csrf-protection, which utilizes the synchronizer token pattern, the '_csrf' attribute is preserved from the unauthenticated session to the authenticated one. An attacker can perform a 'cookie tossing' attack to fixate a known CSRF token in the victim's browser. Once the victim authenticates, the attacker can use the fixated token to perform Cross-Site Request Forgery (CSRF) attacks. The issue is resolved in versions 1.1.0 and 2.3.0 by introducing a default behavior that clears session attributes on login.

Affected products

  • Fastify @fastify/passport <= 1.0.1, 2.0.0 <= 2.2.0

Timeline

  • 2023-04-21: advisory: GitHub Security Advisory published
  • 2023-04-21: patched: Fix committed to repository

References