Vulnerabilities/

Improper Authorization in @sap-cloud-sdk/core

Severity:
High

Description

Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.

Recommendation

Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sap-cloud-sdk/core
Anything's wrong? Let us know Last updated on January 09, 2023