CVE-2019-13483

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
25/07/2019
Last modified:
31/07/2019

Description

Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:auth0:passport-sharepoint:*:*:*:*:*:*:*:* 0.4.0 (excluding)


References to Advisories, Solutions, and Tools