Vulnerabilities > Auth0 > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-08-29 | CVE-2018-15121 | Cross-Site Request Forgery (CSRF) vulnerability in Auth0 Aspnet and Aspnet-Owin An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. | 8.8 |
2018-04-04 | CVE-2018-6874 | Cross-Site Request Forgery (CSRF) vulnerability in Auth0 Auth0.Js CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled. | 8.8 |
2018-03-06 | CVE-2018-7307 | Cross-Site Request Forgery (CSRF) vulnerability in Auth0 Auth0.Js The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter. | 8.8 |
2017-12-27 | CVE-2017-16897 | Authentication Bypass by Spoofing vulnerability in Auth0 Passport-Wsfed-Saml2 A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. | 8.1 |
2017-12-06 | CVE-2017-17068 | Information Exposure vulnerability in Auth0 Auth0.Js A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. | 7.5 |