GHSA-6g6m-m6h5-w9gf
Authorization bypass in express-jwt
Quick fix
GHSA-6g6m-m6h5-w9gf — express-jwt: upgrade to the fixed version with the command below.
npm install express-jwt@6.0.0Details
### Overview Versions before and including 5.3.3, we are not enforcing the **algorithms** entry to be specified in the configuration. When **algorithms** is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass.
### Am I affected? You are affected by this vulnerability if all of the following conditions apply:
You are using express-jwt AND You do not have **algorithms** configured in your express-jwt configuration. AND You are using libraries such as jwks-rsa as the **secret**.
### How to fix that? Specify **algorithms** in the express-jwt configuration. The following is an example of a proper configuration
``` const checkJwt = jwt({ secret: jwksRsa.expressJwtSecret({ rateLimit: true, jwksRequestsPerMinute: 5, jwksUri: `https://${DOMAIN}/.well-known/jwks.json` }), // Validate the audience and the issuer. audience: process.env.AUDIENCE, issuer: `https://${DOMAIN}/`, // restrict allowed algorithms algorithms: ['RS256'] }); ```
### Will this update impact my users? The fix provided in patch will not affect your users if you specified the algorithms allowed. The patch now makes **algorithms** a required configuration.
### Credit IST Group
Are you affected?
Enter the version of the package you're using.