Versions of Passport-SharePoint prior to 0.4.0 do not validate the signature of an before processing.This vulnerability allows attackers to forge tokens and bypass authentication and authorization mechanisms.
Developers using the Passport-SharePoint library must upgrade to version 0.4.0.Please note that Auth0 has deprecated and will no longer maintain this library. Developers should plan to discontinue its use.