HIGH 8.8 npm
Auth0-js bypasses CSRF checks
GHSA-wpq7-q8j4-72jg · CVE-2018-7307
Published · Modified
Description
The Auth0.js library has a vulnerability affecting versions below 9.3 that allows an attacker to bypass the CSRF check from the state parameter if it's missing from the authorization response, leaving the client vulnerable to CSRF attacks.
Ready to move
Start Securing
Free, no credit card | First findings in minutes