Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-07-25T19:34:58

Updated: 2019-07-25T19:34:58

Reserved: 2019-07-10T00:00:00


Link: CVE-2019-13483

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-07-25T20:15:11.730

Modified: 2019-07-31T16:23:30.027


Link: CVE-2019-13483

JSON object: View

cve-icon Redhat Information

No data.

CWE