CVE-2022-2421: Socket.io - Improper type validation in attachment parsing
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
Other sources
Due to improper type validation in the socket.io-parser library (which is used by the socket.io and socket.io-client packages to encode and decode Socket.IO packets), it is possible to overwrite the placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.
Example:
js const decoder = new Decoder();
decoder.on("decoded", (packet) => { console.log(packet.data); // prints [ 'hello', [Function: splice] ] })
decoder.add('51-["hello",{"placeholder":true,"num":"splice"}]'); decoder.add(Buffer.from("world"));
This bubbles up in the socket.io package:
js io.on("connection", (socket) => { socket.on("hello", (val) => { // here, "val" could be a function instead of a buffer }); });
:warning: IMPORTANT NOTE :warning:
You need to make sure that the payload that you received from the client is actually a Buffer object:
js io.on("connection", (socket) => { socket.on("hello", (val) => { if (!Buffer.isBuffer(val)) { socket.disconnect(); return; } // ... }); });
If that's already the case, then you are not impacted by this issue, and there is no way an attacker could make your server crash (or escalate privileges, ...).
Example of values that could be sent by a malicious user:
- a number that is out of bounds
Sample packet: 451-["hello",{"placeholder":true,"num":10}]
js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is undefined }); });
- a value that is not a number, like undefined
Sample packet: 451-["hello",{"placeholder":true,"num":undefined}]
js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is undefined }); });
- a string that is part of the prototype of Array, like "push"
Sample packet: 451-["hello",{"placeholder":true,"num":"push"}]
js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is a reference to the "push" function }); });
- a string that is part of the prototype of Object, like "hasOwnProperty"
Sample packet: 451-["hello",{"placeholder":true,"num":"hasOwnProperty"}]
js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is a reference to the "hasOwnProperty" function }); });
This should be fixed by:
- https://github.com/socketio/socket.io-parser/commit/b5d0cb7dc56a0601a09b056beaeeb0e43b160050, included in socket.io-parser@4.2.1 - https://github.com/socketio/socket.io-parser/commit/b559f050ee02bd90bd853b9823f8de7fa94a80d4, included in socket.io-parser@4.0.5 - https://github.com/socketio/socket.io-parser/commit/04d23cecafe1b859fb03e0cbf6ba3b74dff56d14, included in socket.io-parser@3.4.2 - https://github.com/socketio/socket.io-parser/commit/fb21e422fc193b34347395a33e0f625bebc09983, included in socket.io-parser@3.3.3
Dependency analysis for the socket.io package
| socket.io version | socket.io-parser version | Covered? | |---------------------|---------------------------------------------------------------------------------------------------------|------------------------| | 4.5.2...latest | ~4.2.0 (ref) | Yes :heavycheckmark: | | 4.1.3...4.5.1 | ~4.0.4 (ref) | Yes :heavycheckmark: | | 3.0.5...4.1.2 | ~4.0.3 (ref) | Yes :heavycheckmark: | | 3.0.0...3.0.4 | ~4.0.1 (ref) | Yes :heavycheckmark: | | 2.3.0...2.5.0 | ~3.4.0 (ref) | Yes :heavycheckmark: |
Dependency analysis for the socket.io-client package
| socket.io-client version | socket.io-parser version | Covered? | |----------------------------|----------------------------------------------------------------------------------------------------------------|------------------------------------| | 4.5.0...latest | ~4.2.0 (ref) | Yes :heavycheckmark: | | 4.3.0...4.4.1 | ~4.1.1 (ref) | No, but the impact is very limited | | 3.1.0...4.2.0 | ~4.0.4 (ref) | Yes :heavycheckmark: | | 3.0.5 | ~4.0.3 (ref) | Yes :heavycheckmark: | | 3.0.0...3.0.4 | ~4.0.1 (ref) | Yes :heavycheckmark: | | 2.2.0...2.5.0 | ~3.3.0 (ref) | Yes :heavycheckmark: |
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2421?
CVE-2022-2421 is a vulnerability in the Socket.io js library that allows an attacker to overwrite the _placeholder object, potentially placing references to functions in the resulting query object.
What is the severity of CVE-2022-2421?
The severity of CVE-2022-2421 is critical with a severity value of 9.8.
Which software is affected by CVE-2022-2421?
The Socket.io-parser library versions 4.0.5 and 4.1.0 to 4.2.1 running on Node.js are affected by CVE-2022-2421.
How can an attacker exploit CVE-2022-2421?
An attacker can exploit CVE-2022-2421 by leveraging the improper type validation in attachment parsing to overwrite the _placeholder object and place references to functions in the resulting query object.
Is there a fix available for CVE-2022-2421?
Yes, it is recommended to update to a version of the Socket.io-parser library that is not affected by CVE-2022-2421.