Описание
Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.
Ссылки
- Release Notes
- ExploitVendor Advisory
- ExploitThird Party Advisory
- Release Notes
- ExploitVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.0.0 (включая) до 4.6.0 (исключая)
cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.66479
Средний
7.5 High
CVSS3
8.2 High
CVSS3
Дефекты
CWE-287
CWE-287
Связанные уязвимости
github
почти 3 года назад
Strapi does not verify the access or ID tokens issued during the OAuth flow
EPSS
Процентиль: 98%
0.66479
Средний
7.5 High
CVSS3
8.2 High
CVSS3
Дефекты
CWE-287
CWE-287