Записи auth0
41 опубликованных записей вендора auth0.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 80,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-287 Improper Authentication6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-863 Incorrect Authorization3
- CWE-20 Improper Input Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
41 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2015-9235Proof of concept | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetauth0 · jsonwebtoken · CWE-20 | Критическая9,8 | — | 8,7 % | 29 мая 2018 г. |
40В плане | CVE-2020-7947Эксплойта нет | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 · CWE-1236 | Критическая9,8 | — | 2,8 % | 1 апр. 2020 г. |
40В плане | CVE-2018-6873Эксплойта нет | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.auth0 · auth0.js · CWE-287 | Критическая9,8 | — | 2,2 % | 4 апр. 2018 г. |
40В плане | CVE-2019-7644Эксплойта нет | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Критическая9,8 | — | 1,7 % | 11 апр. 2019 г. |
39Наблюдать | CVE-2026-34236Эксплойта нет | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Критическая9,8 | — | 0,3 % | 1 апр. 2026 г. |
36Наблюдать | CVE-2020-7948Эксплойта нет | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 | Высокая8,8 | — | 2,2 % | 1 апр. 2020 г. |
36Наблюдать | CVE-2020-15084Эксплойта нет | Authorization bypass in express-jwtauth0 · express-jwt · CWE-285 | Критическая9,1 | — | 1,1 % | 30 июн. 2020 г. |
36Наблюдать | CVE-2020-15240Эксплойта нет | Regression in JWT Signature Validationauth0 · omniauth-auth0 · CWE-287 | Критическая9,1 | — | 0,8 % | 21 окт. 2020 г. |
35Наблюдать | CVE-2020-15259Эксплойта нет | CSRF in Auth0 ad-ldap-connectorauth0 · ad\/ldap connector · CWE-352 | Высокая8,8 | — | 1,0 % | 6 нояб. 2020 г. |
35Наблюдать | CVE-2021-41246Эксплойта нет | Session fixation in express-openid-connectauth0 · express openid connect · CWE-384 | Высокая8,8 | — | 0,9 % | 9 дек. 2021 г. |
35Наблюдать | CVE-2020-5391Эксплойта нет | Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.auth0 · wp-auth0 · CWE-352 | Высокая8,8 | — | 0,8 % | 1 апр. 2020 г. |
35Наблюдать | CVE-2018-6874Эксплойта нет | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.auth0 · auth0.js · CWE-352 | Высокая8,8 | — | 0,7 % | 4 апр. 2018 г. |
35Наблюдать | CVE-2018-7307Эксплойта нет | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.auth0 · auth0.js · CWE-352 | Высокая8,8 | — | 0,5 % | 6 мар. 2018 г. |
35Наблюдать | CVE-2018-15121Эксплойта нет | An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.auth0 · aspnet · CWE-352 | Высокая8,8 | — | 0,5 % | 28 авг. 2018 г. |
32Наблюдать | CVE-2017-16897Эксплойта нет | A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.auth0 · passport-wsfed-saml2 · CWE-290 | Высокая8,1 | — | 1,4 % | 27 дек. 2017 г. |
32Наблюдать | CVE-2022-23539Эксплойта нет | jsonwebtoken unrestricted key type could lead to legacy keys usageauth0 · jsonwebtoken · CWE-327 | Высокая8,1 | — | 0,5 % | 22 дек. 2022 г. |
30Наблюдать | CVE-2020-15125Эксплойта нет | Authorization header is not sanitized in an error object in auth0auth0 · auth0.js · CWE-209 | Высокая7,7 | — | 1,5 % | 29 июл. 2020 г. |
30Наблюдать | CVE-2017-17068Эксплойта нет | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.auth0 · auth0.js · CWE-200 | Высокая7,5 | — | 1,4 % | 6 дек. 2017 г. |
30Наблюдать | CVE-2019-16929Эксплойта нет | Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tauth0 · auth0.net · CWE-287 | Высокая7,5 | — | 0,9 % | 8 окт. 2019 г. |
30Наблюдать | CVE-2022-23505Эксплойта нет | Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationauth0 · passport-wsfed-saml2 · CWE-287 | Высокая7,5 | — | 0,8 % | 13 дек. 2022 г. |
30Наблюдать | CVE-2022-23540Эксплойта нет | jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()auth0 · jsonwebtoken · CWE-287 | Высокая7,6 | — | 0,5 % | 22 дек. 2022 г. |
30Наблюдать | CVE-2025-68129Эксплойта нет | Auth0-PHP SDK has Improper Audience Validationauth0 · auth0-php · CWE-863 | Высокая7,5 | — | 0,4 % | 17 дек. 2025 г. |
30Наблюдать | CVE-2025-65945Proof of concept | auth0/node-jws improper HMAC signature verification vulnerabilityauth0 · node-jws · CWE-347 | Высокая7,5 | — | 0,2 % | 4 дек. 2025 г. |
29Наблюдать | CVE-2019-13483Эксплойта нет | Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.auth0 · passport-sharepoint · CWE-345 | Высокая7,3 | — | 0,6 % | 25 июл. 2019 г. |
28Наблюдать | CVE-2026-42280Эксплойта нет | Improper Permission Checking in Auth.js SDKauth0 · auth0.js · CWE-863 | Высокая7,1 | — | 0,3 % | 27 мая 2026 г. |
- CVE-2015-923542В плане
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmet
КритическаяCVSS 9,8Proof of conceptEPSS 9 %auth0 · jsonwebtoken29 мая 2018 г.
- CVE-2020-794740В плане
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %auth0 · login by auth01 апр. 2020 г.
- CVE-2018-687340В плане
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %auth0 · auth0.js4 апр. 2018 г.
- CVE-2019-764440В плане
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %auth0 · auth0-wcf-service-jwt11 апр. 2019 г.
- CVE-2026-3423639Наблюдать
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %auth0 · auth0-php1 апр. 2026 г.
- CVE-2020-794836Наблюдать
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %auth0 · login by auth01 апр. 2020 г.
- CVE-2020-1508436Наблюдать
Authorization bypass in express-jwt
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %auth0 · express-jwt30 июн. 2020 г.
- CVE-2020-1524036Наблюдать
Regression in JWT Signature Validation
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %auth0 · omniauth-auth021 окт. 2020 г.
- CVE-2020-1525935Наблюдать
CSRF in Auth0 ad-ldap-connector
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %auth0 · ad\/ldap connector6 нояб. 2020 г.
- CVE-2021-4124635Наблюдать
Session fixation in express-openid-connect
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %auth0 · express openid connect9 дек. 2021 г.
- CVE-2020-539135Наблюдать
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %auth0 · wp-auth01 апр. 2020 г.
- CVE-2018-687435Наблюдать
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %auth0 · auth0.js4 апр. 2018 г.
- CVE-2018-730735Наблюдать
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %auth0 · auth0.js6 мар. 2018 г.
- CVE-2018-1512135Наблюдать
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %auth0 · aspnet28 авг. 2018 г.
- CVE-2017-1689732Наблюдать
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %auth0 · passport-wsfed-saml227 дек. 2017 г.
- CVE-2022-2353932Наблюдать
jsonwebtoken unrestricted key type could lead to legacy keys usage
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %auth0 · jsonwebtoken22 дек. 2022 г.
- CVE-2020-1512530Наблюдать
Authorization header is not sanitized in an error object in auth0
ВысокаяCVSS 7,7Эксплойта нетEPSS 2 %auth0 · auth0.js29 июл. 2020 г.
- CVE-2017-1706830Наблюдать
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %auth0 · auth0.js6 дек. 2017 г.
- CVE-2019-1692930Наблюдать
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID t
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %auth0 · auth0.net8 окт. 2019 г.
- CVE-2022-2350530Наблюдать
Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %auth0 · passport-wsfed-saml213 дек. 2022 г.
- CVE-2022-2354030Наблюдать
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %auth0 · jsonwebtoken22 дек. 2022 г.
- CVE-2025-6812930Наблюдать
Auth0-PHP SDK has Improper Audience Validation
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %auth0 · auth0-php17 дек. 2025 г.
- CVE-2025-6594530Наблюдать
auth0/node-jws improper HMAC signature verification vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 0 %auth0 · node-jws4 дек. 2025 г.
- CVE-2019-1348329Наблюдать
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %auth0 · passport-sharepoint25 июл. 2019 г.
- CVE-2026-4228028Наблюдать
Improper Permission Checking in Auth.js SDK
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %auth0 · auth0.js27 мая 2026 г.