CVE-2023-51701: @fastify-reply-from JSON Content-Type parsing confusion
Impact
The main repo of fastify use fast-content-type-parse to parse request Content-Type, which will trim after split.
The fastify-reply-from have not use this repo to unify the parse of Content-Type, which won't trim.
As a result, a reverse proxy server built with @fastify/reply-from could misinterpret the incoming body by passing an header ContentType: application/json ; charset=utf-8. This can lead to bypass of security checks.
Patches
@fastify/reply-from v9.6.0 include the fix.
Workarounds
There are no known workarounds.
References
Hackerone Report: https://hackerone.com/reports/2295770.
Other sources
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with @fastify/reply-from could misinterpret the incoming body by passing an header ContentType: application/json ; charset=utf-8. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from version 9.6.0.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51701?
CVE-2023-51701 is classified as a moderate severity vulnerability.
How do I fix CVE-2023-51701?
To fix CVE-2023-51701, upgrade the @fastify/reply-from package to version 9.6.0 or later.
What is the impact of CVE-2023-51701?
The impact of CVE-2023-51701 involves issues with parsing the Content-Type of requests which can lead to unexpected behavior.
Which versions are affected by CVE-2023-51701?
Versions of @fastify/reply-from prior to 9.6.0 are affected by CVE-2023-51701.
Is CVE-2023-51701 related to the fastify framework?
Yes, CVE-2023-51701 is related to the fastify framework, specifically its use of the fast-content-type-parse module.