Impact
The vulnerability arises from the team join endpoint accepting any Content‑Type, including text/plain, which bypasses the sameSite cookie restriction and allows the attacker to auto‑submit a form that forces the victim's browser to authenticate to the attacker's team. This results in the victim unknowingly solving challenges under the attacker's identity and any sensitive data they submit to the Juice Shop instance being stored in the attacker's instance.
Affected Systems
Affected product: juice‑shop multi‑juicer, versions 8.0.0 through 10.0.0. The issue was fixed in version 10.0.1.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity; the EPSS score is less than 1%, suggesting low likelihood of exploitation. The vulnerability is exploit‑agnostic of authentication – an attacker simply hosts a malicious HTML form and lures a victim who has network access to the deployment to load the page. The attack is browser‑based and requires no special infrastructure. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment