auth0 Vulnerabilities and Affected Products
Vulnerabilities associated with laravel-auth0.
Products
Clear product- nextjs-auth07 vulnerabilities
- auth0-PHP4 vulnerabilities
- lock3 vulnerabilities
- node-jsonwebtoken3 vulnerabilities
- passport-wsfed-saml23 vulnerabilities
- auth0.js2 vulnerabilities
- express-openid-connect2 vulnerabilities
- ad-ldap-connector1 vulnerability
- express-jwt1 vulnerability
- laravel-auth01 vulnerability
- Login by Auth01 vulnerability
- node-auth01 vulnerability
- node-jws1 vulnerability
- omniauth-auth01 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
auth0-PHP: Improper File Type Handling in Bulk User Importauth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications built with the SDK does not validate the file-path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs. The vulnerability affects any application that either directly uses the Auth0-PHP SDK (versions 3.3.0–8.16.0) or indirectly relies on those versions through the Auth0/symfony, Auth0/laravel-auth0… | CVSS3.3v3.1 | EPSS0.329% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |