Strapi 3.2.1 until 4.6.0 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.
{ "nvd_published_at": "2023-04-19T16:15:07Z", "github_reviewed_at": "2023-04-24T18:43:51Z", "github_reviewed": true, "severity": "MODERATE", "cwe_ids": [] }