Vulnerability library
Security checkJanuary 09, 2023

Improper Authorization in @sap-cloud-sdk/core

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.

Recommendation

Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 1.19.0, < 1.21.2
  • Patched version(s): 1.21.2

References

Could your website be exposed too?

SmartScanner can check your website for Improper Authorization in @sap-cloud-sdk/core and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 09, 2023