Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.