CVE-2019-16929: High severity auth0 vulnerability
Published Oct 8, 2019
·Updated
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
Affected Software
2 affected componentsFixes available
nuget/Auth0.AuthenticationApi>=5.8.0<6.5.4
6.5.4
Auth0 auth0.net>=5.8.0<=6.5.3
Event History
Oct 8, 2019
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
Description
Oct 24, 2019
Advisory Published
08:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-16929?
CVE-2019-16929 has a severity rating that indicates a potential risk of incorrect access control.
2
How do I fix CVE-2019-16929?
To fix CVE-2019-16929, update Auth0.AuthenticationApi to version 6.5.4 or later.
3
What versions are affected by CVE-2019-16929?
CVE-2019-16929 affects Auth0.AuthenticationApi versions from 5.8.0 up to 6.5.3 inclusive.
4
What is the impact of CVE-2019-16929?
The impact of CVE-2019-16929 is related to the incorrect validation of untrusted ID tokens, leading to potential unauthorized access.
5
Are there any known exploits for CVE-2019-16929?
As of now, there are no publicly known exploits specifically targeting CVE-2019-16929.