CVE-2020-7787 is a high-severity authentication bypass vulnerability affecting all versions of the react-adal package. It allows an attacker to forge a JWT token and have it treated as authentic due to improper validation of nonce, session, and refresh values stored in browser local or session storage. The flaw stems from how these values are stored with appended "||" delimiters, leading to an empty string always being considered a valid value. The vulnerability has a CVSS score of 8.2 (High) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N, indicating it can be exploited remotely with low attack complexity, requiring no user interaction, and resulting in high confidentiality impact and low integrity impact. The EPSS score is low, suggesting a low probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with a large percentage of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:react-adal_project:react-adal:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.