Executive brief
Strapi's authentication plugin is vulnerable to an open redirect attack combined with session token exposure, allowing unauthenticated attackers to steal third-party authentication tokens and bypass authentication. By tricking a user to click a malicious link, an attacker can redirect them to an attacker-controlled domain while intercepting authentication tokens, potentially gaining unauthorized access to Strapi applications that rely on SSO providers.
Technical details
The vulnerability consists of two chained flaws in @strapi/plugin-users-permissions: (1) an open redirect in the OAuth callback handler that fails to validate the callback URL parameter, allowing redirection to arbitrary external domains; (2) session authentication tokens being transmitted as URL query parameters, making them capturable by an attacker's domain. An attacker constructs a malicious link to /api/connect/{provider}?callback=https://attacker.com/, and when a user clicks it, the application redirects to the provider's authentication flow and then to the attacker's domain with the SSO token in the URL. The attack requires user interaction (a single click) but does not require prior authentication. Patches are available in version 4.24.2 and later.
Affected products
- Strapi users-permissions <= 4.24.1
Timeline
- 2024-06-12: disclosed: Advisory published
- 2024-06-12: patched: Fixed in version 4.24.2