In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authentication Bypass vulnerabilities in an interactive lesson.
Start learningUpgrade @strapi/plugin-users-permissions
to version 4.6.0 or higher.
@strapi/plugin-users-permissions is a headless CMS
Affected versions of this package are vulnerable to Authentication Bypass when using the AWS Cognito login provider's None
signing algorithm during the OAuth flow.
NOTE: After upgrading to the fixed version the AWS Cognito provider must be reconfigured to include the JWKS URL.