VYPR

React Adal

by React Adal Project

CVEs (1)

  • CVE-2020-7787HigDec 9, 2020
    risk 0.46cvss 8.2epss 0.01

    This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to treat an attacker-generated JWT token as authentic. The…