VDB
Sign up
HIGH7.7

GHSA-6g6m-m6h5-w9gf

Authorization bypass in express-jwt

Quick fix

GHSA-6g6m-m6h5-w9gf — express-jwt: upgrade to the fixed version with the command below.

npm install express-jwt@6.0.0

Details

### Overview Versions before and including 5.3.3, we are not enforcing the **algorithms** entry to be specified in the configuration. When **algorithms** is not specified in the configuration, with the combination of jwks-rsa, it may lead to authorization bypass.

### Am I affected? You are affected by this vulnerability if all of the following conditions apply:

You are using express-jwt AND You do not have **algorithms** configured in your express-jwt configuration. AND You are using libraries such as jwks-rsa as the **secret**.

### How to fix that? Specify **algorithms** in the express-jwt configuration. The following is an example of a proper configuration

``` const checkJwt = jwt({ secret: jwksRsa.expressJwtSecret({ rateLimit: true, jwksRequestsPerMinute: 5, jwksUri: `https://${DOMAIN}/.well-known/jwks.json` }), // Validate the audience and the issuer. audience: process.env.AUDIENCE, issuer: `https://${DOMAIN}/`, // restrict allowed algorithms algorithms: ['RS256'] }); ```

### Will this update impact my users? The fix provided in patch will not affect your users if you specified the algorithms allowed. The patch now makes **algorithms** a required configuration.

### Credit IST Group

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-jwt
Introduced in: 0Fixed in: 6.0.0
Fixnpm install express-jwt@6.0.0

References