UNKNOWN npm

Strapi does not verify the access or ID tokens issued during the OAuth flow

GHSA-583x-23h9-f5w7 · CVE-2023-22893

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Strapi 3.2.1 until 4.6.0 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.

Ready to move

Start Securing

Free, no credit card | First findings in minutes