Description
AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.
Remediation
Upgrade to the latest version of Strapi
References
Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Related Vulnerabilities
WordPress Plugin Thrive Clever Widgets Security Bypass (1.56)
WordPress Plugin NAB Transact Security Bypass (2.1.0)
WordPress Plugin Advanced Custom Fields:reCAPTCHA Field Security Bypass (1.1.1)
WordPress Plugin WP Courses LMS Security Bypass (2.0.28)
WordPress Plugin Abandoned Cart Lite for WooCommerce Security Bypass (5.14.2)