CVE-2025-27371
CVSS 3.1 Score 6.9 of 10 (medium)
Details
Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 305
Summary
CVE-2025-27371 affects certain IETF OAuth 2.0 specifications, specifically the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism. The vulnerability lies in ambiguous audience values of JSON Web Tokens (JWTs) sent to authorization servers. The impacted RFCs may include RFC 7523, as well as RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR). These ambiguities could potentially lead to unintended access or misuse of protected resources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.