Vulnerability GHSA-9xww-74xv-gjfp
Summary
Http4s: DigestAuth allows replay of captured requests
Details
The DigestAuth replay defence stores lastNc + 1 rather than the nonce-count (nc) value it just accepted. When a legitimate client sends non-contiguous nc values (parallel or retried requests, as browsers do), the server's counter lags behind the highest nc seen, and a captured Authorization header can be replayed multiple times.
Impact
A passive observer can turn one captured Digest-authenticated request into several replayed authenticated (state-changing) requests, defeating the core replay protection Digest provides over Basic.
Preconditions
- Application uses
DigestAuth. - Attacker can passively observe at least one legitimate digest request.
- Legitimate client emits an
ncmore than one greater than the last, for instance from a parallel or retried request.
Workarounds
- Deploy over TLS so requests cannot be captured.
Related Vulnerabilities
Other vulnerabilities affecting the same packages