Description
AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.
Remediation
Upgrade to the latest version of Strapi
References
Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Gift Cards Security Bypass (1.3.7)
WordPress Plugin WooCommerce Anti-Fraud Security Bypass (3.2)
WordPress Plugin Theme Blvd Widget Areas Multiple Security Bypass Vulnerabilities (1.2.2)
CData Jetty Path Traversal (CVE-2024-31848/CVE-2024-31849/CVE-2024-31850/CVE-2024-31851)