{"id":"GHSA-r2vw-jgq9-jqx2","aliases":[],"url":"https://o3.security/vulnerability/GHSA-r2vw-jgq9-jqx2","summary":"Improper Authorization in @sap-cloud-sdk/core","details":"Affected versions of `@sap-cloud-sdk/core` do not properly validate JWTs.  The `verifyJwt()` function does not properly validate the URL from where the public verification key for the JWT can be downloaded.  Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.\n\n\n## Recommendation\n\nUpgrade to version 1.21.2 or later.","published":"2020-09-03T15:54:11Z","modified":"2020-08-31T19:02:48Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@sap-cloud-sdk/core","fixedVersion":"1.21.2"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1540"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T19:02:48Z"}}