Description
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
Remediation
References
https://github.com/KANIXB/JWTIssues/blob/main/Certification%20Verification%20issue%20in%20light-oauth2.md
https://github.com/networknt/light-oauth2/issues/369
Related Vulnerabilities
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2022-37423 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2020-28270 Vulnerability in npm package object-hierarchy-access
CVE-2018-1999020 Vulnerability in maven package org.onosproject:onos-core-common
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wfs