Mass assignment

Mass assignment

Description

Mass assignment occurs when client input, such as JSON, is merged into an object through Object.assign or a similar function without validation. An attacker may overwrite fields the application does not allow them to change, including sensitive properties that control permissions, settings, or data.

Potential impact

  • Unauthorized changes to a user's permissions or privilege level
  • Exposure or modification of sensitive data and changes to service behavior through internal properties or settings

Remediation

  • Select only allowed fields before merging user input with Object.assign or similar functions.
  • Use an allow-list of server-approved properties and validate each value's type and business rules.
  • Do not let client input change sensitive fields managed by the server, such as permissions.

Examples

Before

The database lookup and storage helpers are omitted from these excerpts.

javascript
// Before
function updateUser(untrustedInput) {
  let user = getUserFromDB();
  // Merge unvalidated input
  Object.assign(user, JSON.parse(untrustedInput));
  saveUserToDB(user);
}

After

javascript
// After
function updateUser(untrustedInput) {
  let user = getUserFromDB();
  const allowed = ['nickname', 'email'];
  const data = JSON.parse(untrustedInput);
  // Merge only allowed fields
  for(const key of allowed) {
    if(data[key] !== undefined) {
      user[key] = data[key];
    }
  }
  saveUserToDB(user);
}

Explanation:

  • Before: Passing user input directly to Object.assign lets the caller overwrite system properties, potentially including administrative permissions.
  • After: Only fields on the allow-list are merged, preventing unauthorized changes to other sensitive properties.

References