RSS   Vulnerabilities for 'Auth0.js'   RSS

2020-04-09
 
CVE-2020-5263

CWE-522
 

 
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the user entered. If the error object is exposed or logged without modification, the application risks password exposure. This is fixed in version 9.12.3

 
2018-04-04
 
CVE-2018-6874

CWE-352
 

 
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

 
 
CVE-2018-6873

CWE-287
 

 
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

 

 >>> Vendor: Auth0 12 Products
Auth0.js
Aspnet
Aspnet-owin
Passport-sharepoint
Jsonwebtoken
LOCK
Login by auth0
Wp-auth0
Express-jwt
Auth0
Nextjs-auth0
Express openid connect


Copyright 2024, cxsecurity.com

 

Back to Top