CVE-2022-31070
JavaScript vulnerability analysis and mitigation

Overview

NestJS Proxy is a NestJS module designed to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library contained a security vulnerability where sensitive cookies (e.g., session cookies) could be inadvertently forwarded to backend services configured by the application developer (NVD).

Technical details

The vulnerability stems from the library's lack of cookie filtering functionality. Before version 0.7.0, there was no mechanism to prevent sensitive cookies from being automatically forwarded to backend services, which could lead to unintended exposure of sensitive authentication data (NVD).

Impact

The vulnerability could result in sensitive cookies being inadvertently exposed to backend services that should not have access to them. This could potentially compromise session security and user authentication data (NVD).

Mitigation and workarounds

The issue has been fixed in version 0.7.0 of @finastra/nestjs-proxy. The patched version blocks cookies from being forwarded by default, with developers able to configure an allow-list of cookie names using the allowedCookies config setting. Users of @ffdc/nestjs-proxy are advised that this package has been deprecated and should update their package.json file to use @finastra/nestjs-proxy instead (NVD).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management