VDB
Sign up
CRITICAL

GHSA-f38f-jvqj-mfg6

NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access

Quick fix

GHSA-f38f-jvqj-mfg6 — @haxtheweb/haxcms-nodejs: upgrade to the fixed version with the command below.

npm install @haxtheweb/haxcms-nodejs@11.0.7

Details

### Summary The NodeJS version of HAX CMS uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks.

### Details If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication.

![insecure-default-configuration-code](https://github.com/user-attachments/assets/af58b08a-8a26-4ef5-8deb-e6e9d4efefaa)

#### Affected Resources - [package.json:13](https://github.com/haxtheweb/haxcms-nodejs/blob/a4d2f18341ff63ad2d97c35f9fc21af8b965248b/package.json#L13)

### PoC To reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without JWT checks enabled.

### Impact Without security checks in place, an unauthenticated remote attacker could access, modify, and delete all site information.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@haxtheweb/haxcms-nodejs
Introduced in: 0Fixed in: 11.0.7
Fixnpm install @haxtheweb/haxcms-nodejs@11.0.7

References