Junglewise Threat Intelligence

express-laravel-passport authentication bypass in JWT validation

Severity: info · Published 2020-09-04

Vendors: npm.

Executive brief

express-laravel-passport is a Node.js library for integrating Laravel Passport authentication with Express applications. The package fails to properly validate JSON Web Tokens (JWTs), allowing attackers to craft forged tokens and impersonate any user, gaining unauthorized access to protected API endpoints and data.

Technical details

The vulnerability is an authentication bypass in JWT validation (CWE-287). All versions of express-laravel-passport prior to 2.0.5 fail to properly validate JWTs, allowing attackers to send HTTP requests with forged or manipulated tokens to impersonate other users. The attack requires network access to affected endpoints but typically does not require authentication to the legitimate service itself—an attacker can craft a token offline. The flaw allows complete bypass of intended access controls, granting attackers the ability to read and modify data as any user. A patch is available in version 2.0.5 and later.

Affected products

  • npm express-laravel-passport < 2.0.5

Timeline

  • 2020-09-04: disclosed

References