{"id":"GHSA-3fjj-p79j-c9hh","summary":"Fastify: Incorrect Content-Type parsing can lead to CSRF attack ","details":"### Impact\n\nThe attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Type’s [essence](https://mimesniff.spec.whatwg.org/#mime-type-essence) as \"application/x-www-form-urlencoded\", \"multipart/form-data\", or \"text/plain\", could potentially be used to invoke routes that only accepts `application/json` content type, thus bypassing any [CORS protection](https://fetch.spec.whatwg.org/#simple-header), and therefore they could lead to a  Cross-Site Request Forgery attack.\n\n### Patches\nFor `4.x` users, please update to at least `4.10.2`\nFor `3.x` users, please update to at least `3.29.4`\n\n### Workarounds\n\nImplement Cross-Site Request Forgery protection using [`@fastify/csrf`](https://www.npmjs.com/package/@fastify/csrf).\n\n### References\n\nCheck out the HackerOne report: https://hackerone.com/reports/1763832.\n\n### For more information\n\n[Fastify security policy](https://github.com/fastify/fastify/security/policy)\n","aliases":["CVE-2022-41919"],"modified":"2023-11-08T04:10:35.631515Z","published":"2022-11-21T22:28:11Z","database_specific":{"nvd_published_at":"2022-11-22T20:15:00Z","cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-21T22:28:11Z"},"references":[{"type":"WEB","url":"https://github.com/fastify/fastify/security/advisories/GHSA-3fjj-p79j-c9hh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41919"},{"type":"WEB","url":"https://github.com/fastify/fastify/commit/62dde76f1f7aca76e38625fe8d983761f26e6fc9"},{"type":"PACKAGE","url":"https://github.com/fastify/fastify"},{"type":"WEB","url":"https://www.npmjs.com/package/@fastify/csrf"}],"affected":[{"package":{"name":"fastify","ecosystem":"npm","purl":"pkg:npm/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-3fjj-p79j-c9hh/GHSA-3fjj-p79j-c9hh.json"}},{"package":{"name":"fastify","ecosystem":"npm","purl":"pkg:npm/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.29.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-3fjj-p79j-c9hh/GHSA-3fjj-p79j-c9hh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}