First published: Tue Oct 08 2019(Updated: )
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Auth0.AuthenticationApi | >=5.8.0<6.5.4 | 6.5.4 |
Auth0 auth0.net | >=5.8.0<=6.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16929 has a severity rating that indicates a potential risk of incorrect access control.
To fix CVE-2019-16929, update Auth0.AuthenticationApi to version 6.5.4 or later.
CVE-2019-16929 affects Auth0.AuthenticationApi versions from 5.8.0 up to 6.5.3 inclusive.
The impact of CVE-2019-16929 is related to the incorrect validation of untrusted ID tokens, leading to potential unauthorized access.
As of now, there are no publicly known exploits specifically targeting CVE-2019-16929.