Vulnerabilities/

Improper Authorization in passport-cognito

Severity:
High

Description

All versions of passport-cognito are vulnerable to Improper Authorization. The package fails to properly scope the variables containing authorization information, such as access token, refresh token and ID token. This causes a race condition where simultaneous authenticated users may receive authorization tokens for a different user.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
passport-cognito
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing