oidcc is vulnerable to Authentication Bypass
76
High Risk
The library validates OpenID Connect ID tokens and JARM responses that can arrive as encrypted JWE objects. When an encrypted token wraps unsigned plaintext claims instead of a properly signed nested JWS, the verification path treats the token as fully validated and never enforces a signature. This lets unauthenticated callers forge identity tokens by encrypting arbitrary claims to the relying party's public encryption key, impersonating any user and enabling account takeover. The fix rejects encrypted tokens that lack a verified signature before any claims are trusted.
You are affected if you are using a version that falls within the vulnerable range and you have configured the client with an encryption key so it accepts encrypted ID tokens or JARM responses.
oidcc is vulnerable to Authentication Bypass in versions 3.2.0 - 3.8.0.
Upgrade the oidcc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.