Strapi 3.2.1 until 4.6.0 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.
{
"severity": "MODERATE",
"github_reviewed_at": "2023-04-24T18:43:51Z",
"cwe_ids": [],
"nvd_published_at": "2023-04-19T16:15:07Z",
"github_reviewed": true
}