CVE-2023-22893
Strapi does not verify the access or ID tokens issued during the OAuth flow
EPSS 4.2%
描述
Strapi 3.2.1 until 4.6.0 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.
如何修補 CVE-2023-22893
要修補 CVE-2023-22893,請將受影響套件升級到下列已修補版本。
- npm/@strapi/plugin-users-permissions—升級至 4.6.0 或更新版本
CVE-2023-22893 正在被利用嗎?
低 — EPSS 為 4.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 3.2.1, < 4.6.0