Описание
light-oauth2 missing public key verification
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
Пакеты
Наименование
com.networknt:light-oauth2
maven
Затронутые версииВерсия исправления
< 2.1.27
2.1.27
Связанные уязвимости
CVSS3: 5.9
nvd
больше 2 лет назад
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.