Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| passport-sharepoint(npm) | 0 | 0.4.0 | N/A |
CVSS Metrics