Document 000000001, No Login Required — JavaScript Bug Hunt

Modelled on the First American Financial exposure (May 2019): document URLs used sequential IDs and the endpoint performed no authorization check.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Authorization
  • Modelled on: First American · 2019
  • Visible tests: the owner can read their document; another user is refused; an anonymous caller is refused
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the First American Financial exposure (May 2019): document URLs used sequential IDs and the endpoint performed no authorization check. Changing the number in the URL walked 885 million records of mortgage paperwork, including bank statements and social security numbers.

documents.js returns any document whose id is requested.

Fix getDocument so a caller may only read documents they own.

Bug report

BUG-FAF2019 · Priority: Critical (IDOR) · Reported by: security

getDocument(store, docId, session) must return { status, doc }:

  • { status: 401, doc: null } when session is missing or has no userId
  • { status: 404, doc: null } when the document does not exist
  • { status: 403, doc: null } when the document's ownerId is not the caller
  • { status: 200, doc } otherwise

Observed: any id returns the document, with or without a session.

Logs

[docs] served doc 000000002 to anonymous caller
[docs] 885,000,000 documents enumerable by incrementing the id

The code as shipped

src/docs/documents.js (editable)

// Fetches a document by id.
exports.getDocument = function (store, docId, session) {
  var doc = store[docId];
  return { status: 200, doc: doc };
};

Read-only context: src/docs/MODEL.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.