Duende.BFF 2.2.1
This is a security patch release. It fixes a vulnerability in Duende.BFF.Yarp. We recommend that all users of the YARP integration upgrade.
The fix changes default behavior. Read Breaking changes below before you upgrade.
The same fix is released in 3.1.1, 3.0.1, 2.3.1 and 2.2.1, and for 4.x in 4.3.1, 4.2.1, 4.1.3 and 4.0.4.
Security fixes
- The YARP integration no longer forwards the
Cookieheader (GHSA-vvg7-p7jw-8qr3). Routes proxied through the BFF's YARP integration (AddReverseProxy().AddBffExtensions()) forwarded the incomingCookieheader to the remote API. That header includes the BFF session cookie, which was sent along with the access token. The BFF now removes theCookieheader from requests on all YARP routes, asMapRemoteBffApiEndpointalready did.
Breaking changes
-
YARP routes no longer forward cookies to remote APIs. If an upstream API needs cookies from the browser, you can turn this off for the whole application with the new
BffOptions.RemoveCookieHeaderFromYarpRequestsoption:builder.Services.AddBff(options => { options.RemoveCookieHeaderFromYarpRequests = false; });
With the option set to
false, YARP forwards cookies as before. You can then control cookie forwarding per route with standard YARP transforms, for exampleRequestHeaderRemove: Cookie. Only do this for upstream APIs you trust with the BFF session cookie.