Description
All versions of passport-cognito
are vulnerable to Improper Authorization. The package fails to properly scope the variables containing authorization information, such as access token, refresh token and ID token. This causes a race condition where simultaneous authenticated users may receive authorization tokens for a different user.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Related Issues
- static-server Path Traversal vulnerability - CVE-2023-26152
- chromedriver Downloads Resources over HTTP - CVE-2016-10579
- Denial of service in http-proxy-middleware - CVE-2024-21536
- parse is vulnerable to prototype pollution - CVE-2025-57324
- Tags:
- npm
- passport-cognito
Anything's wrong? Let us know Last updated on January 09, 2023