PT-2023-18757 · Amazon · Aws Cognito
Ghostccamm
·
Published
2023-04-18
·
Updated
2025-11-07
·
CVE-2023-22893
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi versions 3.2.1 through 4.5.5
Description
The issue arises from the lack of verification of access or ID tokens issued during the OAuth flow when using the AWS Cognito login provider for authentication. This allows a remote attacker to forge an ID token signed with the 'None' type algorithm, bypassing authentication and potentially impersonating any user who uses AWS Cognito for authentication.
Recommendations
For versions 3.2.1 through 4.5.5, update to a version that includes the fix for this issue to prevent authentication bypass and impersonation.
As a temporary workaround, consider restricting the use of the AWS Cognito login provider until a patch is available.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aws Cognito