light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.networknt:light-oauth2(Maven) | 0 | 2.1.27 | N/A |
CVSS Metrics