Description
Mass assignment occurs when client input, such as JSON, is merged into an object through Object.assign or a similar function without validation. An attacker may overwrite fields the application does not allow them to change, including sensitive properties that control permissions, settings, or data.
Potential impact
- Unauthorized changes to a user's permissions or privilege level
- Exposure or modification of sensitive data and changes to service behavior through internal properties or settings
Remediation
- Select only allowed fields before merging user input with
Object.assignor similar functions. - Use an allow-list of server-approved properties and validate each value's type and business rules.
- Do not let client input change sensitive fields managed by the server, such as permissions.
Examples
Before
The database lookup and storage helpers are omitted from these excerpts.
javascript
// Before
function updateUser(untrustedInput) {
let user = getUserFromDB();
// Merge unvalidated input
Object.assign(user, JSON.parse(untrustedInput));
saveUserToDB(user);
}
After
javascript
// After
function updateUser(untrustedInput) {
let user = getUserFromDB();
const allowed = ['nickname', 'email'];
const data = JSON.parse(untrustedInput);
// Merge only allowed fields
for(const key of allowed) {
if(data[key] !== undefined) {
user[key] = data[key];
}
}
saveUserToDB(user);
}
Explanation:
- Before: Passing user input directly to
Object.assignlets the caller overwrite system properties, potentially including administrative permissions. - After: Only fields on the allow-list are merged, preventing unauthorized changes to other sensitive properties.