Document 000000001, No Login Required — JavaScript Bug Hunt
Modelled on the First American Financial exposure (May 2019): document URLs used sequential IDs and the endpoint performed no authorization check.
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Authorization
- Modelled on: First American · 2019
- Visible tests: the owner can read their document; another user is refused; an anonymous caller is refused
- Reward: 50 XP for a complete fix
Briefing
Modelled on the First American Financial exposure (May 2019): document URLs used sequential IDs and the endpoint performed no authorization check. Changing the number in the URL walked 885 million records of mortgage paperwork, including bank statements and social security numbers.
documents.js returns any document whose id is requested.
Fix getDocument so a caller may only read documents they own.
Bug report
BUG-FAF2019 · Priority: Critical (IDOR) · Reported by: security
getDocument(store, docId, session) must return { status, doc }:
- { status: 401, doc: null } when session is missing or has no userId
- { status: 404, doc: null } when the document does not exist
- { status: 403, doc: null } when the document's ownerId is not the caller
- { status: 200, doc } otherwise
Observed: any id returns the document, with or without a session.
Logs
[docs] served doc 000000002 to anonymous caller
[docs] 885,000,000 documents enumerable by incrementing the idThe code as shipped
src/docs/documents.js (editable)
// Fetches a document by id.
exports.getDocument = function (store, docId, session) {
var doc = store[docId];
return { status: 200, doc: doc };
};
Read-only context: src/docs/MODEL.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.