First published: Wed Apr 04 2018(Updated: )
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Auth0 Auth0.js | <=8.12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6874 is classified as a high severity vulnerability due to its impact on authentication processes.
To fix CVE-2018-6874, disable the Legacy Lock API flag in your Auth0 configuration.
CVE-2018-6874 is caused by a Cross-Site Request Forgery (CSRF) vulnerability resulting from a flaw in the Auth0 authentication service.
CVE-2018-6874 affects Auth0.js versions up to and including 8.12.1 when the Legacy Lock API flag is enabled.
Yes, CVE-2018-6874 is exploitable if an attacker can induce a user to perform actions without their consent while authenticated.