Junglewise Threat Intelligence

CVE-2024-45607: whatsapp-api-js improper cryptographic signature verification

CVE-2024-45607 · Severity: low · CVSS 3.1 · Published 2024-09-12

Vendors: npm.

Executive brief

whatsapp-api-js is a Node.js library for integrating WhatsApp messaging functionality into applications. The library contains a flaw in its message signature validation that allows attackers to send forged messages without valid cryptographic authentication, potentially leading to message spoofing or system manipulation.

Technical details

The vulnerability is an improper cryptographic signature verification (CWE-347) in the verifyRequestSignature and post methods of whatsapp-api-js versions 4.0.0 through 4.0.2. The signature validation logic is inverted or absent, allowing any request to bypass authentication checks. An attacker can craft malicious messages on the network without requiring authentication or user interaction. This enables message forgery and could allow attackers to inject unauthorized WhatsApp messages into applications using this library. The issue was patched in version 4.0.3.

Affected products

  • whatsapp-api-js whatsapp-api-js 4.0.0 through 4.0.2

Timeline

  • 2024-09-12: disclosed
  • 2024-09-12: patched: Version 4.0.3 released

References