Junglewise Threat Intelligence

CVE-2023-38704: import-in-the-middle unsanitized input in module generation

CVE-2023-38704 · Severity: low · CVSS 3.1 · Published 2023-08-08

Vendors: npm, Datadog.

Executive brief

import-in-the-middle is a Node.js loader that intercepts ECMAScript module imports to enable instrumentation and monitoring. The library dynamically generates wrapper code based on module names without proper sanitization, allowing attackers to inject malicious code if an application passes untrusted input to import() calls. This can lead to complete compromise of applications using the loader with user-controllable module paths.

Technical details

The vulnerability is a code injection flaw (CWE-20: Improper Input Validation) in the module generation logic of import-in-the-middle. The loader constructs wrapper modules on-the-fly by concatenating the module specifier into generated source code without sanitization. When an application calls import() with user-controlled input, an attacker can inject arbitrary code that will be executed in the wrapper module's context. The attack vector is network-based with high complexity (requiring the attacker to influence the input passed to import()), but scope is changed, giving the attacker access beyond the vulnerable component. No authentication is required. The vulnerability was patched in version 1.4.2 by implementing URL sanitization.

Affected products

  • Datadog import-in-the-middle <= 1.4.1

Timeline

  • 2023-08-07: disclosed: Advisory published
  • 2023-08-08: patched: Fix released in version 1.4.2

References