CVE-2023-31580

Publication date

2023-10-24 00:00:00

Family

mitre

State

PUBLISHED

Description

light-oauth2 before version 2.1.27 obtains the public key without any verification. This could allow attackers to authenticate to the application with a crafted JWT token.