Description
light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
Remediation
References
https://github.com/KANIXB/JWTIssues/blob/main/Certification%20Verification%20issue%20in%20light-oauth2.md
https://github.com/networknt/light-oauth2/issues/369
Related Vulnerabilities
CVE-2019-10744 Vulnerability in npm package lodash
CVE-2020-5259 Vulnerability in maven package org.webjars.bowergithub.dojo:dojox
CVE-2020-7642 Vulnerability in npm package lazysizes
CVE-2022-0853 Vulnerability in maven package jboss:jboss-client
CVE-2023-29522 Vulnerability in maven package org.xwiki.platform:xwiki-platform-xclass-ui