CVE-2017-17068: Infoleak

Published Dec 6, 2017
·
Updated

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().

Other sources

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().

Affected Software

2 affected componentsFixes available
npm/auth0-js<8.12.0
8.12.0
Auth0 auth0.js<8.12

Event History

Dec 6, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Dec 21, 2017
Advisory Published
12:47 AM

Frequently Asked Questions

1

What is the severity of CVE-2017-17068?

CVE-2017-17068 is classified as a high-severity vulnerability due to its potential to expose users' tokens.

2

How do I fix CVE-2017-17068?

To fix CVE-2017-17068, upgrade the auth0.js library to version 8.12.0 or higher.

3

What applications are affected by CVE-2017-17068?

CVE-2017-17068 affects versions of the auth0.js library prior to 8.12.0 that utilize popup callback pages.

4

What type of vulnerability is CVE-2017-17068?

CVE-2017-17068 is classified as a cross-origin vulnerability.

5

Who discovered CVE-2017-17068?

CVE-2017-17068 was disclosed by independent security researchers identifying risks associated with the auth0.js library.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203