Description
Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.
Recommendation
Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.19.0, < 1.21.2
- Patched version(s): 1.21.2
References
Related Issues
- Unauthorized access to data in @sap-cloud-sdk/core - CVE-2021-41251
- Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript - Vulnerability
- MCPHub has an Improper Authorization vulnerability via its handleSseConnection function - CVE-2025-11287
- Improper Authorization in react-oauth-flow - Vulnerability
You might also like:
- Tags:
- npm
- @sap-cloud-sdk/core
Anything's wrong? Let us know Last updated on January 09, 2023


