CVE-2023-31580

Published
View on NVD ↗
CVSS v3
5.9
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.

A fast, light and cloud native OAuth 2.0 authorization microservices based on light-4j
GitHubGitHub
314
This repository contains some cryptographic issues in the libraries used for JWT.
GitHubGitHub