Record summary

CVE-2023-22893 has a selected CVSS score of 8.2 (high); EIP currently links 1 Nuclei template.

Description

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 23, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

@strapi/plugin-users-permissions

Browse npm / @strapi/plugin-users-permissions
GitHub Advisory3.2.1 to < 4.6.0 · Fixed in 4.6.0affected

Nuclei templates

1
ProjectDiscoveryHIGHStrapi Versions <=4.5.6 - Authentication BypassCVSS 7.5

Strapi through 4.5.5 does not verify the access or ID tokens issued during the OAuth flow when the AWS Cognito login provider is used for authentication. A remote attacker could forge an ID token that is signed using the 'None' type algorithm to bypass authentication and impersonate any user that use AWS Cognito for authentication.

Impact

Unauthenticated attackers can forge JWT tokens using the "None" algorithm to bypass AWS Cognito authentication and impersonate any Strapi user, gaining unauthorized access to CMS content and administrative functions.

Remediation

Update Strapi to version 4.5.6 or later which properly verifies access and ID tokens issued during OAuth flow with AWS Cognito login provider.

WeaknessesCWE-287
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2023strapiauthenticatedawscognitovkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
FOFA: app="strapi-Headless-CMS"

Source: ProjectDiscovery

References

9