Description
AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.
Remediation
Upgrade to the latest version of Strapi
References
Security Disclosure of Vulnerabilities: CVE-2023-22893, CVE-2023-22621, and CVE-2023-22894
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1
Related Vulnerabilities
WordPress Plugin Duplicator-WordPress Migration Security Bypass (0.5.8)
WordPress Plugin ImportWP-Import any XML or CSV File into WordPress Security Bypass (1.1.5)
WordPress Plugin YITH Color and Label Variations for WooCommerce Security Bypass (1.8.11)
Joomla! Core 1.6.x Security Bypass (1.6.0 - 1.6.6)
WordPress Plugin WooCommerce Multi Currency-Currency Switcher Security Bypass (2.1.17)