Improper Authentication Affecting react/http package, versions >=0.7.0, <1.7.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.03% (63rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-REACTHTTP-3018097
  • published7 Sept 2022
  • disclosed7 Sept 2022
  • creditMarco Squarcina

Introduced: 7 Sep 2022

CVE-2022-36032  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade react/http to version 1.7.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authentication when ReactPHP is processing incoming HTTP cookie values, by allowing an attacker to forge encoded cookies which decode to cookies with valid prefixes such as __Host- and __Secure-.

Workaround:

Users who are not able to update to the fixed versions can place a reverse proxy in front of the ReactPHP HTTP server to filter out any unexpected Cookie request headers.

CVSS Base Scores

version 3.1