First published: Tue Oct 08 2019(Updated: )
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Auth0.AuthenticationApi | >=5.8.0<6.5.4 | 6.5.4 |
Auth0 auth0.net | >=5.8.0<=6.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.