Junglewise Threat Intelligence

helmet-csp configuration override via browser sniffing

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

helmet-csp is a Node.js library that helps web applications enforce Content Security Policy (CSP) headers, a security mechanism that prevents malicious scripts from running. A flaw in versions before 2.9.1 allows an attacker to circumvent this protection by exploiting browser detection code, which can inadvertently delete the default CSP policy and leave applications vulnerable to cross-site scripting attacks.

Technical details

The vulnerability is a configuration override flaw in helmet-csp's browser sniffing logic for Firefox. When processing requests from Firefox 4, the browserSniff feature incorrectly deletes the default-src CSP directive, which serves as the fallback policy for all unspecified directives. An attacker can craft a request from Firefox 4 (or spoof the User-Agent) to trigger this behavior, effectively removing the application's default CSP and potentially enabling Cross-Site Scripting (XSS) attacks. No authentication or user interaction is required—the vulnerability is network-reachable. The fix was released in version 2.9.1; users can also mitigate the issue by disabling browserSniff configuration in vulnerable versions.

Affected products

  • Helmet helmet-csp before 2.9.1

Timeline

  • 2020-09-03: disclosed: Vulnerability published
  • 2020-09-03: patched: Version 2.9.1 released with fix

References