{"id":"CVE-2019-13483","details":"Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.","aliases":["GHSA-45fh-g845-pj9w"],"modified":"2026-07-08T15:55:30.194733Z","published":"2019-07-25T20:15:11.730Z","references":[{"type":"ADVISORY","url":"https://auth0.com/docs/security/bulletins/cve-2019-13483"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/auth0/passport-sharepoint","events":[{"introduced":"0"},{"fixed":"35b1d3f5377670839d9e58f9678c3a51db4da4c6"}],"database_specific":{"cpe":"cpe:2.3:a:auth0:passport-sharepoint:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.4.0"}],"source":"CPE_RANGE"}}],"versions":["v0.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13483.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}