Junglewise Threat Intelligence

Google API Node.js Client improper authorization in credentials handling

Severity: info · CVSS 0 · Published 2020-09-02

Vendors: npm, Google.

Executive brief

The Google API Node.js Client library is used by developers to access Google services like Gmail from their applications. A flaw in versions before 39.1.0 causes credential settings intended for one client connection to incorrectly apply to all other client connections within the same event loop, potentially allowing requests to be sent with wrong authentication credentials and leading to unauthorized access or data exposure.

Technical details

This vulnerability is an improper authorization issue (CWE-285) stemming from a refactor to use googleapis-common. The root cause is that calling `auth.setCredentials()` on an OAuth2 authentication object has side effects that incorrectly propagate to all other client instances in the same event loop. The vulnerability affects all versions before 39.1.0; no authentication bypass or special network access is required—it is a logical flaw in how credentials are scoped to individual clients. An attacker with control over multiple client instances or application state could trigger this condition to cause requests authenticated with incorrect credentials. The fix is available in version 39.1.0 and later.

Affected products

  • Google API Node.js Client before 39.1.0

Timeline

  • 2020-09-02: disclosed: GHSA advisory published
  • 2020-09-01: patched: Fix available in version 39.1.0

References