Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Passport Sharepoint HIGH 7.3
CVE-2019-13483

Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge token…

Fix: 0.4.0+
Fix from $1,950 2019-07-25
Auth0 Wcf Service Jwt CRITICAL 9.8
CVE-2019-7644

Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature.…

Fix: 1.0.4+
Fix from $2,300 2019-04-11
Aspnet HIGH 8.8
CVE-2018-15121

An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 an…

Mitigation only
Fix from $1,950 2018-08-29
Angular Jwt MEDIUM 6.5
CVE-2018-11537

Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInte…

Fix: 0.1.10+
Fix from $1,600 2018-06-19
Jsonwebtoken CRITICAL 9.8
CVE-2015-9235EPSS 9%

In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (…

Fix: 4.2.2+
Fix from $2,300 2018-05-29
Auth0.js CRITICAL 9.8
CVE-2018-6873

The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

Fix: after 8.10.1
Fix from $2,300 2018-04-04
Auth0.js HIGH 8.8
CVE-2018-6874

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

Fix: after 8.12.1
Fix from $1,950 2018-04-04
Auth0.js HIGH 8.8
CVE-2018-7307

The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.

Fix: 9.3+
Fix from $1,950 2018-03-06
Passport Wsfed Saml2 HIGH 8.1
CVE-2017-16897

A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to im…

Fix: 3.0.5+
Fix from $1,950 2017-12-27
Auth0.js HIGH 7.5
CVE-2017-17068

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to ac…

Fix: 8.12+
Fix from $1,950 2017-12-06