Skip to main content

Vendor archive

auth0 CVEs

Beta · best-effort

41 CVEs tagged to vendor auth04 Critical, 19 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2020-6753

Published Apr 1, 2020

The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-2020-5392.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5392

Published Apr 1, 2020

A stored cross-site scripting (XSS) vulnerability exists in the Auth0 plugin before 4.0.0 for WordPress via the settings page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5391

Published Apr 1, 2020

Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20173

Published Feb 5, 2020

The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20174

Published Feb 3, 2020

Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16929

Published Oct 8, 2019

Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13483

Published Jul 25, 2019

Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge tokens and bypass authentication an…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7644

Published Apr 11, 2019

Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is pres…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15121

Published Aug 29, 2018

An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. Th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11537

Published Jun 19, 2018

Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDom…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9235

Published May 29, 2018

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms bu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6874

Published Apr 4, 2018

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6873

Published Apr 4, 2018

The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7307

Published Mar 6, 2018

The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16897

Published Dec 27, 2017

A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and pot…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17068

Published Dec 6, 2017

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tok…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-41 of 41 CVEsPage 2 of 2