CVE-2025-27371

CVSS 3.1 Score 6.9 of 10 (medium)

Details

Published Mar 3, 2025
Updated: Mar 7, 2025
CWE ID 305

Summary

CVE-2025-27371 affects certain IETF OAuth 2.0 specifications, specifically the JSON Web Token Profile for OAuth 2.0 Client Authentication mechanism. The vulnerability lies in ambiguous audience values of JSON Web Tokens (JWTs) sent to authorization servers. The impacted RFCs may include RFC 7523, as well as RFC 7521, RFC 7522, RFC 9101 (JAR), and RFC 9126 (PAR). These ambiguities could potentially lead to unintended access or misuse of protected resources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share