Description
AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.
Remediation
Upgrade to the latest version of Strapi
References
Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Related Vulnerabilities
WordPress Plugin Starfish Review Generation & Marketing for WordPress Security Bypass (2.0.0)
WordPress Plugin Protected Posts Logout Button Security Bypass (1.4.5)
Akeeba backup access control bypass
Security vulnerability in MySQL/MariaDB sql/password.c
Drupal Core 8.9.x Multiple Security Bypass Vulnerabilities (8.9.0 - 8.9.18)