Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2019-13483 Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing. This allows attackers to forge token… Passport Sharepoint 0.4.0+ Fix from $1,9502019-07-25 CRITICAL 9.8 CVE-2019-7644 Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature.… Auth0 Wcf Service Jwt 1.0.4+ Fix from $2,3002019-04-11 HIGH 8.8 CVE-2018-15121 An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 an… Aspnet Mitigation only Fix from $1,9502018-08-29 MEDIUM 6.5 CVE-2018-11537 Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInte… Angular Jwt 0.1.10+ Fix from $1,6002018-06-19 CRITICAL 9.8 CVE-2015-9235EPSS 9% In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (… Jsonwebtoken 4.2.2+ Fix from $2,3002018-05-29 CRITICAL 9.8 CVE-2018-6873 The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated. Auth0.js after 8.10.1 Fix from $2,3002018-04-04 HIGH 8.8 CVE-2018-6874 CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. Auth0.js after 8.12.1 Fix from $1,9502018-04-04 HIGH 8.8 CVE-2018-7307 The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter. Auth0.js 9.3+ Fix from $1,9502018-03-06 HIGH 8.1 CVE-2017-16897 A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to im… Passport Wsfed Saml2 3.0.5+ Fix from $1,9502017-12-27 HIGH 7.5 CVE-2017-17068 A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to ac… Auth0.js 8.12+ Fix from $1,9502017-12-06