Launch Week Day 1: Announcing Security Design Review
HIGH 8.8 npm

Cross-Site Request Forgery (CSRF) in Auth0

GHSA-wv26-rj8c-4r33 · CVE-2018-6874

Published · Modified

Description

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

Ready to move

Start Securing

Free, no credit card | First findings in minutes