CVE-2023-31580
25.10.2023, 18:17
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.Enginsight
Vendor | Product | Version |
---|---|---|
networknt | light-oauth2 | 𝑥 < 2.1.27 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References