|
| 1 | +id: jwt-simple-noverify-javascript |
| 2 | +language: JavaScript |
| 3 | +severity: warning |
| 4 | +message: >- |
| 5 | + "Detected the decoding of a JWT token without a verify step. JWT tokens |
| 6 | + must be verified before use, otherwise the token's integrity is unknown. |
| 7 | + This means a malicious actor could forge a JWT token with any claims. Set |
| 8 | + 'verify' to `true` before using the token." |
| 9 | +note: >- |
| 10 | + [CWE-287] Improper Authentication |
| 11 | + [CWE-345] Insufficient Verification of Data Authenticity |
| 12 | + [CWE-347] Improper Verification of Cryptographic Signature |
| 13 | + [REFERENCES] |
| 14 | + - https://www.npmjs.com/package/jwt-simple |
| 15 | + - https://cwe.mitre.org/data/definitions/287 |
| 16 | + - https://cwe.mitre.org/data/definitions/345 |
| 17 | + - https://cwe.mitre.org/data/definitions/347 |
| 18 | +rule: |
| 19 | + kind: call_expression |
| 20 | + any: |
| 21 | + - pattern: $JWT.decode($TOKEN, $SECRET, true $$$) |
| 22 | + - pattern: $JWT.decode($TOKEN, $SECRET, "$$$" $$$) |
| 23 | + - pattern: $JWT.decode($TOKEN, $SECRET, '$$$' $$$) |
| 24 | + - pattern: $JWT.decode($TOKEN, $SECRET, `$$$` $$$) |
| 25 | + inside: |
| 26 | + stopBy: end |
| 27 | + follows: |
| 28 | + stopBy: end |
| 29 | + any: |
| 30 | + - kind: lexical_declaration |
| 31 | + all: |
| 32 | + - has: |
| 33 | + stopBy: end |
| 34 | + kind: identifier |
| 35 | + pattern: $JWT |
| 36 | + - has: |
| 37 | + stopBy: end |
| 38 | + kind: call_expression |
| 39 | + pattern: require('jwt-simple') |
| 40 | + - kind: expression_statement |
| 41 | + has: |
| 42 | + stopBy: end |
| 43 | + kind: assignment_expression |
| 44 | + pattern: $JWT = require('jwt-simple') |
0 commit comments