auth0 Vulnerabilities and Affected Products
Vulnerabilities associated with node-auth0.
Products
Clear product- nextjs-auth07 vulnerabilities
- auth0-PHP4 vulnerabilities
- lock3 vulnerabilities
- node-jsonwebtoken3 vulnerabilities
- passport-wsfed-saml23 vulnerabilities
- auth0.js2 vulnerabilities
- express-openid-connect2 vulnerabilities
- ad-ldap-connector1 vulnerability
- express-jwt1 vulnerability
- laravel-auth01 vulnerability
- Login by Auth01 vulnerability
- node-auth01 vulnerability
- node-jws1 vulnerability
- omniauth-auth01 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-15125HIGH | Authorization header is not sanitized in an error object in auth0In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API CWE-209Jul 29, 2020 | CVSS7.7v3.1 | EPSS1.54% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |