Junglewise Threat Intelligence

CVE-2024-47178: basic-auth-connect timing-safe string comparison in authentication

CVE-2024-47178 · Severity: low · CVSS 3.1 · Published 2024-09-30

Vendors: npm.

Executive brief

basic-auth-connect is an Express.js middleware for HTTP Basic Authentication. The library uses a timing-unsafe string comparison when validating credentials, which allows attackers to leak authentication secrets through response-time analysis by measuring how long the comparison takes to reject invalid credentials.

Technical details

The vulnerability is a timing side-channel attack (CWE-208) in basic-auth-connect's credential validation callback. Versions before 1.1.0 use standard string comparison operators instead of constant-time comparison functions, allowing attackers on the network to distinguish valid from invalid credentials by measuring response time differences. The vulnerability requires no authentication or user interaction—any unauthenticated attacker can exploit it by sending crafted HTTP Basic Auth headers and timing the server responses. An attacker can progressively leak valid credentials character-by-character through repeated timing measurements. The fix, released in version 1.1.0, replaces the timing-unsafe comparison with a constant-time equality check.

Affected products

  • Express.js basic-auth-connect <1.1.0

Timeline

  • 2024-09-30: disclosed
  • 2024-09-30: patched: Fixed in version 1.1.0

References