VYPR

Light Oauth2

by Networknt

CVEs (1)

  • CVE-2023-31580MedOct 25, 2023
    risk 0.38cvss 5.9epss 0.01

    light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.