Check CVE Id
Check CWE Id
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
(Insufficient Verification of Data Authenticity)
CVSS Base Score
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication...
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric a...
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
Back to Top