Description
SharePoint has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted JWT token and get full access to the system.
Remediation
Upgrade to the latest version of SharePoint
References
SharePoint Pre-Auth RCE chain (CVE-2023-29357 & CVE-2023-24955)
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Related Vulnerabilities
Ruby Out-of-bounds Write Vulnerability (CVE-2017-11465)
MySQL CVE-2022-21297 Vulnerability (CVE-2022-21297)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2020-15098)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5397)
WordPress Plugin Autopilot SEO for WooCommerce Security Bypass (1.5.1)