Description
AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.
Remediation
Upgrade to the latest version of Strapi
References
Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Related Vulnerabilities
WordPress Plugin MapPress Maps for WordPress Security Bypass (2.54.5)
WordPress Plugin Captchinoo, Google recaptcha for admin login page Security Bypass (2.3)
WordPress Plugin Premium SEO Pack Security Bypass (1.9.1.3)
Joomla! Core improper access check in webservice endpoints
WordPress Plugin SiteGround Security Security Bypass (1.2.5)