{"id":"GHSA-r2vw-jgq9-jqx2","summary":"Improper Authorization in @sap-cloud-sdk/core","details":"Affected versions of `@sap-cloud-sdk/core` do not properly validate JWTs.  The `verifyJwt()` function does not properly validate the URL from where the public verification key for the JWT can be downloaded.  Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.\n\n\n## Recommendation\n\nUpgrade to version 1.21.2 or later.","modified":"2020-08-31T19:02:48Z","published":"2020-09-03T15:54:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-08-31T19:02:48Z","nvd_published_at":null,"cwe_ids":["CWE-285"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1540"}],"affected":[{"package":{"name":"@sap-cloud-sdk/core","ecosystem":"npm","purl":"pkg:npm/%40sap-cloud-sdk/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.19.0"},{"fixed":"1.21.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r2vw-jgq9-jqx2/GHSA-r2vw-jgq9-jqx2.json"}}],"schema_version":"1.9.0"}