Looking for the vulnerability index of Invicti's legacy products?
Strapi Cognito provider Authentication Bypass (CVE-2023-22893) - Vulnerability Database

Strapi Cognito provider Authentication Bypass (CVE-2023-22893)

Description

AWS Cognito login provider of Strapi is vulnerable to an authentication bypass vulnerability due to a lack of JWT signature verification. It allows unauthenticated users to compromise the system.

Remediation

Upgrade to the latest version of Strapi