light-oauth2 missing public key verification
Discription

light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.Read More

Back to Main

Subscribe for the latest news: