Improper Authentication in Auth0.AuthenticationApi
High severity
GitHub Reviewed
Published
Oct 24, 2019
to the GitHub Advisory Database
•
Updated May 30, 2023
Description
Published by the National Vulnerability Database
Oct 8, 2019
Reviewed
Oct 24, 2019
Published to the GitHub Advisory Database
Oct 24, 2019
Last updated
May 30, 2023
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
References