Executive brief
@fastify/session is a session management library for Fastify web applications. A flaw in the library's cookie expiration logic prevents expired sessions from being properly destroyed when the maxAge field is set, allowing attackers to reuse old session cookies to gain unauthorized access to user accounts or session data.
Technical details
The vulnerability is a session expiration bypass (CWE-613) caused by incorrect handling of cookie expiration fields during session restoration. When restoring a cookie from the session store, the expires field is overwritten if the maxAge field is set, preventing the library from correctly detecting expired cookies. This allows an attacker with access to a destroyed or expired session cookie to reuse it for authentication. The vulnerability requires user interaction (the user must visit a site using the vulnerable library) and affects session confidentiality. The fix was released in version 10.9.0.
Affected products
- Fastify @fastify/session < 10.9.0
Timeline
- 2024-05-21: disclosed
- 2024-05-21: patched: v10.9.0