PT-2023-18757 · Amazon · Aws Cognito
Ghostccamm
·
Publicado
2023-04-18
·
Atualizado
2025-11-07
·
CVE-2023-22893
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi versions 3.2.1 through 4.5.5
Description
The issue arises from the lack of verification of access or ID tokens issued during the OAuth flow when using the AWS Cognito login provider for authentication. This allows a remote attacker to forge an ID token signed with the 'None' type algorithm, bypassing authentication and potentially impersonating any user who uses AWS Cognito for authentication.
Recommendations
For versions 3.2.1 through 4.5.5, update to a version that includes the fix for this issue to prevent authentication bypass and impersonation.
As a temporary workaround, consider restricting the use of the AWS Cognito login provider until a patch is available.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aws Cognito