Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40316
HistoryApr 27, 2023 - 1:12 p.m.

Authentication Bypass

2023-04-2713:12:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
strapi
plugin
users permissions
authentication bypass
aws cognito
oauth
remote attacker
impersonation

0.003 Low

EPSS

Percentile

71.4%

@strapi/plugin-users-permissions is vulnerable to Authentication Bypass. When using the AWS Cognito login provider for authentication, the library doesn’t check access or ID tokens generated throughout the OAuth flow. A remote attacker might impersonate any user using AWS Cognito by fabricating an ID token signed using the None type algorithm, bypassing authentication.

0.003 Low

EPSS

Percentile

71.4%