whatsapp-api-js fails to validate message's signature
Moderate severity
GitHub Reviewed
Published
Sep 12, 2024
in
Secreto31126/whatsapp-api-js
•
Updated Sep 12, 2024
Description
Published by the National Vulnerability Database
Sep 12, 2024
Published to the GitHub Advisory Database
Sep 12, 2024
Reviewed
Sep 12, 2024
Last updated
Sep 12, 2024
Impact
Incorrect Access Control, anyone using the post or verifyRequestSignature methods to handle messages is impacted.
Patches
Patched in version 4.0.3.
Workarounds
It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid.
References
Secreto31126/whatsapp-api-js#371
References