https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31580
Source: CVEAnnouncements
Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31580
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token. https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31580 Source: CVEAnnouncements Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31580
|
|