Skip to main content

Vendor/product archive

auth0 / lock CVEs

Beta · best-effort

4 CVEs tagged to auth0 / lock0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2022-29172

Published May 5, 2022

Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32641

Published Jun 4, 2021

auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the libr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15119

Published Aug 20, 2020

In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might b…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20174

Published Feb 3, 2020

Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1