Description
This affects versions of react-adal < 0.5.1. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to treat an attacker-generated JWT token as authentic.
Recommendation
Update the react-adal package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.5.1
- Patched version(s): 0.5.1
References
Could your website be exposed too?
SmartScanner can check your website for Improper Authentication in react-adal and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Credential leak in react-native-fast-image - CVE-2020-7696
- Improper Control of Generation of Code in doT - CVE-2020-8141
- Improper Neutralization of Input During Web Page Generation in CKEditor4 - CVE-2020-27193
- Regular expression denial of service in react-native - CVE-2020-1920


