Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown
CVE-2020-5391
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
0
Attacker Value
Unknown
CVE-2020-5392
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.
0
Attacker Value
Unknown
CVE-2019-20173
Disclosure Date: February 05, 2020 (last updated February 21, 2025)
The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.
0
Attacker Value
Unknown
CVE-2019-20174
Disclosure Date: February 03, 2020 (last updated February 21, 2025)
Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
0
Attacker Value
Unknown
CVE-2019-16929
Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
0
Attacker Value
Unknown
CVE-2019-13483
Disclosure Date: July 25, 2019 (last updated November 27, 2024)
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication and authorization mechanisms.
0
Attacker Value
Unknown
CVE-2019-7644
Disclosure Date: April 11, 2019 (last updated November 27, 2024)
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.
0
Attacker Value
Unknown
CVE-2018-15121
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
0
Attacker Value
Unknown
CVE-2018-11537
Disclosure Date: June 19, 2018 (last updated November 26, 2024)
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
0
Attacker Value
Unknown
CVE-2015-9235
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
0