When opening a form in Valtimo, the access token (JWT) of the user is exposed to api.form.io via the the x-jwt-token header. An attacker can retrieve personal information from this token, or use it to execute requests to the Valtimo REST API on behalf of the logged-in user.
This issue is caused by a misconfiguration of the Form.io component.
The following conditions have to be met in order to perform this attack:
api.form.io domain.x-jwt-token header is logged or otherwise available to the attacker.Versions 10.8.4, 11.1.6 and 11.2.2 have been patched
{
"cwe_ids": [
"CWE-532"
],
"github_reviewed": true,
"github_reviewed_at": "2024-05-13T16:04:55Z",
"nvd_published_at": "2024-05-14T15:39:29Z",
"severity": "CRITICAL"
}