Show filters
35 Total Results
Displaying 31-35 of 35
Sort by:
Attacker Value
Unknown

CVE-2018-6873

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
0
Attacker Value
Unknown

CVE-2018-6874

Disclosure Date: April 04, 2018 (last updated November 26, 2024)
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
0
Attacker Value
Unknown

CVE-2018-7307

Disclosure Date: March 06, 2018 (last updated November 26, 2024)
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
0
Attacker Value
Unknown

CVE-2017-16897

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).
0
Attacker Value
Unknown

CVE-2017-17068

Disclosure Date: December 06, 2017 (last updated November 26, 2024)
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().
0