CVE-2022-31142 is a high-severity vulnerability affecting the @fastify/bearer-auth and fastify-bearer-auth plugins, which are used to enforce bearer Authorization headers. The vulnerability stems from an insecure implementation of crypto.timingSafeEqual, allowing an attacker to estimate the length of a valid bearer token, thereby aiding in brute-force attacks due to the limited character set of base64 tokens. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no user interaction, making it easily exploitable over the network to achieve high confidentiality impact. While there are no known workarounds, patched versions 7.0.2 and 8.0.1 of @fastify/bearer-auth address the issue. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.1, < 7.0.2CPE matchmatch criteria | cpe:2.3:a:fastify:bearer-auth:*:*:*:*:*:node.js:*:* | ||
8.0.0CPE matchmatch criteria | cpe:2.3:a:fastify:bearer-auth:8.0.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.