PKSA-bkkv-pqnd-d5ym Security Advisory
- 
                        [HIGH] Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVerifier.php does not verify for token signature that can result in JWT with any email address and user ID could be forged from an actual token, or from thin air.PKSA-bkkv-pqnd-d5ym CVE-2018-1000025 GHSA-4gjj-r7w8-42cq Affected package: kreait/firebase-php Affected version: >=3.2.0,<3.8.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories