Description
SharePoint has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted JWT token and get full access to the system.
Remediation
Upgrade to the latest version of SharePoint
References
SharePoint Pre-Auth RCE chain (CVE-2023-29357 & CVE-2023-24955)
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Related Vulnerabilities
Oracle Database Server CVE-2019-2956 Vulnerability (CVE-2019-2956)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0837)
IBM WebSEAL Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-4707)