Authentication Bypass Affecting @strapi/plugin-users-permissions package, versions >=4.0.0-next.0 <4.6.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-STRAPIPLUGINUSERSPERMISSIONS-5431308
- published 20 Apr 2023
- disclosed 18 Apr 2023
- credit ghostccamm
How to fix?
Upgrade @strapi/plugin-users-permissions
to version 4.6.0 or higher.
Overview
@strapi/plugin-users-permissions is a headless CMS
Affected versions of this package are vulnerable to Authentication Bypass when using the AWS Cognito login provider's None
signing algorithm during the OAuth flow.
NOTE: After upgrading to the fixed version the AWS Cognito provider must be reconfigured to include the JWKS URL.
References
CVSS Scores
version 3.1