Executive brief
Redbird is a reverse proxy library used to route and forward web traffic. Versions prior to 0.9.1 enable deprecated and vulnerable TLS 1.0 connections by default with no option to disable them, potentially allowing attackers to downgrade encrypted connections and intercept sensitive data in transit.
Technical details
The vulnerability is an insecure default configuration (CWE-20) in redbird's proxy server implementation (lib/proxy.js). Versions before 0.9.1 enable TLS 1.0 connections without providing configuration options to disable them. TLS 1.0 is cryptographically weak and subject to known attacks. The vulnerability is remotely exploitable by a network attacker capable of intercepting traffic. Exploitation requires an attacker to perform a man-in-the-middle attack to force a downgrade to TLS 1.0. Version 0.9.1 adds support for the "secureOptions" configuration parameter, allowing administrators to disable older TLS versions.
Affected products
- redbird redbird before 0.9.1
Timeline
- 2019-06-06: disclosed: Advisory published
- 2019-04-30: patched: Fix merged in version 0.9.1