Overview
Versions of Passport-SharePoint prior to 0.4.0 do not validate the signature of an before processing. This vulnerability allows attackers to forge tokens and bypass authentication and authorization mechanisms.Am I affected?
You are affected by this vulnerability if you use a Passport-SharePoint version earlier than 0.4.0.How do I fix this?
Developers using the Passport-SharePoint library must upgrade to version0.4.0
.
Please note that Auth0 has deprecated and will no longer maintain this library. Developers should plan to discontinue its use.