Executive brief
@fastify/oauth2 is a Node.js library that handles OAuth2 authentication flows for Fastify web applications. The library reused a single static state parameter across all users and requests, allowing attackers to forge authentication redirects and hijack user OAuth2 sessions. This could enable account takeover or unauthorized access to connected services.
Technical details
@fastify/oauth2 versions before 7.2.0 generated a single static OAuth2 state parameter at startup and reused it for all users and requests, violating OAuth2 security best practices. The state parameter is intended to prevent Cross-Site Request Forgery (CSRF) attacks by ensuring each authorization request has a unique, user-bound value. An attacker could forge a malicious redirect URL with the known static state, tricking a user into clicking it and potentially intercepting their OAuth2 authorization flow. The vulnerability requires user interaction (clicking a link) and scope change (affecting the OAuth2 provider). Fixed in v7.2.0, which generates unique state per user, stores it in HTTP-only cookies with SameSite=Lax protection, and changes checkStateFunction signature to accept the full Request object.
Affected products
- Fastify @fastify/oauth2 < 7.2.0
Timeline
- 2023-07-05: disclosed: Advisory published on GitHub
- 2023-07-05: patched: Fixed in v7.2.0