Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown
CVE-2018-6873
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
0
Attacker Value
Unknown
CVE-2018-6874
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
0
Attacker Value
Unknown
CVE-2018-7307
Disclosure Date: March 06, 2018 (last updated November 26, 2024)
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
0
Attacker Value
Unknown
CVE-2017-16897
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).
0
Attacker Value
Unknown
CVE-2017-17068
Disclosure Date: December 06, 2017 (last updated November 26, 2024)
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().
0