ZeroHour

CVE-2019-13483

CVSS 3.0
7.3 high
EPSS
<1%p45
Published
()
Modified
Description

Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.

Vendors
auth0
Products
passport-sharepoint
Weakness
CWE-345
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.