{"id":"CVE-2023-22893","details":"Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.","aliases":["GHSA-583x-23h9-f5w7"],"modified":"2026-08-12T03:51:44.231621581Z","published":"2023-04-19T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22893.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22893.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22893"},{"type":"PACKAGE","url":"https://github.com/strapi/strapi/releases"},{"type":"ARTICLE","url":"https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve"},{"type":"ARTICLE","url":"https://www.ghostccamm.com/blog/multi_strapi_vulns/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/strapi/strapi","events":[{"introduced":"6bb7a7f198b13b0780547285d4214704ce991c23"},{"fixed":"8f1988367c1ccbbb1c44866d9dc9fa512e4f3b31"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.5.5"},{"introduced":"3.0.0"},{"fixed":"4.6.0"}],"source":["DESCRIPTION","CPE_RANGE"],"cpe":"cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22893.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}