{"id":"GHSA-g8x5-p9qc-cf95","summary":"@fastify/oauth2 vulnerable to Cross Site Request Forgery due to reused Oauth2 state","details":"### Impact\n\nAll versions of @fastify/oauth2 used a statically generated `state` parameter at startup time and were used across all requests for all users.\nThe purpose of the Oauth2 `state` parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in some way that will allow the server to validate it.\n\n### Patches\n\nv7.2.0 changes the default behavior to store the `state` in a cookie with the `http-only` and `same-site=lax` attributes set. The state is now by default generated for every user.\n\nNote that this contains a breaking change in the `checkStateFunction` function, which now accepts the full `Request` object.\n\n### Workarounds\n\nThere are no known workarounds.\n\n### References\n\n* [Prevent Attacks and Redirect Users with OAuth 2.0 State Parameters](https://auth0.com/docs/secure/attack-protection/state-parameters)\n","aliases":["CVE-2023-31999"],"modified":"2023-11-08T04:12:32.265455Z","published":"2023-07-05T21:36:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-05T21:36:56Z","nvd_published_at":"2023-07-03T17:15:09Z","cwe_ids":["CWE-352"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/fastify/fastify-oauth2/security/advisories/GHSA-g8x5-p9qc-cf95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-35935"},{"type":"WEB","url":"https://github.com/fastify/fastify-oauth2/commit/bff756b456cbb769080631af2beb85671ff4c79c"},{"type":"WEB","url":"https://auth0.com/docs/secure/attack-protection/state-parameters"},{"type":"PACKAGE","url":"https://github.com/fastify/fastify-oauth2"},{"type":"WEB","url":"https://github.com/fastify/fastify-oauth2/releases/tag/v7.2.0"}],"affected":[{"package":{"name":"@fastify/oauth2","ecosystem":"npm","purl":"pkg:npm/%40fastify/oauth2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-g8x5-p9qc-cf95/GHSA-g8x5-p9qc-cf95.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"}]}