n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it matched an incoming JWT to a local user on the sub claim alone and ignored iss. A valid token from issuer A carrying a sub that belongs to someone under issuer B logged you in as them.
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Originally reported by The Hacker News
0 comments
No comments yet. Be the first to start the discussion.