PT-2023-18757 · Amazon · Aws Cognito

Ghostccamm

·

Publicado

2023-04-18

·

Atualizado

2025-11-07

·

CVE-2023-22893

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions 3.2.1 through 4.5.5
Description The issue arises from the lack of verification of access or ID tokens issued during the OAuth flow when using the AWS Cognito login provider for authentication. This allows a remote attacker to forge an ID token signed with the 'None' type algorithm, bypassing authentication and potentially impersonating any user who uses AWS Cognito for authentication.
Recommendations For versions 3.2.1 through 4.5.5, update to a version that includes the fix for this issue to prevent authentication bypass and impersonation. As a temporary workaround, consider restricting the use of the AWS Cognito login provider until a patch is available.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22893
GHSA-583X-23H9-F5W7

Produtos afetados

Aws Cognito