CVE-2019-13483: High severity auth0 passport vulnerability
Published Jul 25, 2019
·Updated
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
Affected Software
1 affected component
Auth0 Passport-SharePoint<0.4.0
Event History
Jul 25, 2019
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13483?
The severity of CVE-2019-13483 is rated as high with a score of 7.3.
2
How can I fix CVE-2019-13483?
To fix CVE-2019-13483, update Auth0 Passport-SharePoint to version 0.4.0 or above, which includes validation of the JWT signature of an Access Token before processing.
3
What does CVE-2019-13483 vulnerability allow attackers to do?
CVE-2019-13483 allows attackers to forge tokens and bypass authentication and authorization mechanisms by not validating the JWT signature of an Access Token.