First published: Thu Jul 25 2019(Updated: )
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Auth0 Passport-SharePoint | <0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-13483 is rated as high with a score of 7.3.
To fix CVE-2019-13483, update Auth0 Passport-SharePoint to version 0.4.0 or above, which includes validation of the JWT signature of an Access Token before processing.
CVE-2019-13483 allows attackers to forge tokens and bypass authentication and authorization mechanisms by not validating the JWT signature of an Access Token.