Junglewise Threat Intelligence

CVE-2024-29041: Express.js open redirect in malformed URLs

CVE-2024-29041 · Severity: low · CVSS 3.1 · Published 2024-03-25

Technologies: Express.js Express.

Executive brief

Express.js is a widely-used web application framework for Node.js. Applications using Express redirect functions with user-provided URLs can be tricked into redirecting users to attacker-controlled websites, bypassing security controls. An attacker can exploit this by crafting a malformed URL that passes validation checks, potentially leading to credential theft, malware distribution, or phishing attacks.

Technical details

This is an open redirect vulnerability (CWE-601, CWE-1286) affecting the res.location() and res.redirect() methods in Express.js versions prior to 4.19.2 and 5.0.0-beta.3. The vulnerability exists because Express encodes user-provided URLs using encodeurl before adding them to the location header, but this encoding can cause malformed URLs to be evaluated unexpectedly by redirect allowlist implementations. An attacker can craft a specially-formatted URL that bypasses the application's allow-list checks, causing legitimate users (who must click a link) to be redirected to an attacker-controlled site. The fix involves pre-parsing URLs using Node.js built-in URL parsing (require('node:url').parse or new URL) before passing them to the redirect functions. Patches are available in Express 4.19.2 and 5.0.0-beta.3.

Affected products

  • Express.js Express <4.19.2, >=5.0.0-alpha.1 <5.0.0-beta.3

Timeline

  • 2024-03-25: disclosed: Vulnerability published in GHSA-rv95-896h-c2vc
  • 2024-03-25: patched: Express 4.19.2 and 5.0.0-beta.3 released with fixes

References