Vulnerabilities > Auth0 > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-23 CVE-2022-23539 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Auth0 Jsonwebtoken
Versions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification.
network
low complexity
auth0 CWE-327
8.1
2022-12-22 CVE-2022-23540 Improper Verification of Cryptographic Signature vulnerability in Auth0 Jsonwebtoken
In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to signature validation bypass due to defaulting to the `none` algorithm for signature verification.
network
low complexity
auth0 CWE-347
7.6
2022-12-13 CVE-2022-23505 Unspecified vulnerability in Auth0 Passport-Wsfed-Saml2
Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport.
network
low complexity
auth0
7.5
2020-04-01 CVE-2020-7947 Injection vulnerability in Auth0 Login BY Auth0
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
network
low complexity
auth0 CWE-74
7.5
2019-07-25 CVE-2019-13483 Insufficient Verification of Data Authenticity vulnerability in Auth0 Passport-Sharepoint 0.3.0
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.
network
low complexity
auth0 CWE-345
7.5
2019-04-11 CVE-2019-7644 Information Exposure Through an Error Message vulnerability in Auth0 Auth0-Wcf-Service-Jwt
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature.
network
low complexity
auth0 CWE-209
7.5
2018-05-29 CVE-2015-9235 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Auth0 Jsonwebtoken
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
network
low complexity
auth0 CWE-327
7.5
2018-04-04 CVE-2018-6873 Improper Authentication vulnerability in Auth0 Auth0.Js
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
network
low complexity
auth0 CWE-287
7.5