Junglewise Threat Intelligence

CVE-2024-34706: Valtimo components JWT token exposure to Form.io

CVE-2024-34706 · Severity: low · CVSS 3.1 · Published 2024-05-13

Executive brief

@valtimo/components is a front-end library used in the Valtimo platform to render forms and manage user interfaces. The library inadvertently sends users' authentication tokens (JWT) to external Form.io servers, allowing attackers with network visibility to intercept these tokens and impersonate users or access sensitive data. An attacker can use a stolen token to execute API requests as the compromised user for up to 5 minutes after token generation.

Technical details

The vulnerability is a sensitive information disclosure (CWE-532) caused by improper configuration of the Form.io component integration. When a user opens a form in Valtimo, the application sends the user's JWT access token to api.form.io via the x-jwt-token HTTP header. An attacker positioned to observe network traffic to Form.io (e.g., ISP, CDN compromise, DNS hijacking) can capture this token and decode it to extract user identity and claims, or replay it against the Valtimo REST API within the token's time-to-live window (default 5 minutes in Keycloak). The attack requires network access to both Form.io and the Valtimo API, but no user interaction or authentication. Patches are available in versions 10.8.4, 11.1.6, and 11.2.2.

Affected products

  • Valtimo Platform @valtimo/components < 10.8.4, >= 11.0.0 < 11.1.6, >= 11.2.0 < 11.2.2

Timeline

  • 2024-05-13: disclosed
  • 2024-05-13: patched: Versions 10.8.4, 11.1.6, 11.2.2 released

References