auth0 kayıtları
auth0 üreticisine ait 41 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %80,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-287 Improper Authentication6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-863 Incorrect Authorization3
- CWE-20 Improper Input Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
41 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2015-9235Kavram kanıtı | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetauth0 · jsonwebtoken · CWE-20 | Kritik9,8 | — | %8,7 | 29 May 2018 |
40Planlayın | CVE-2020-7947İstismar yok | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 · CWE-1236 | Kritik9,8 | — | %2,8 | 1 Nis 2020 |
40Planlayın | CVE-2018-6873İstismar yok | The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.auth0 · auth0.js · CWE-287 | Kritik9,8 | — | %2,2 | 4 Nis 2018 |
40Planlayın | CVE-2019-7644İstismar yok | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Kritik9,8 | — | %1,7 | 11 Nis 2019 |
39İzleyin | CVE-2026-34236İstismar yok | Auth0 PHP SDK Insufficient Entropy in Cookie Encryptionauth0 · auth0-php · CWE-331 | Kritik9,8 | — | %0,3 | 1 Nis 2026 |
36İzleyin | CVE-2020-7948İstismar yok | An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.auth0 · login by auth0 | Yüksek8,8 | — | %2,2 | 1 Nis 2020 |
36İzleyin | CVE-2020-15084İstismar yok | Authorization bypass in express-jwtauth0 · express-jwt · CWE-285 | Kritik9,1 | — | %1,1 | 30 Haz 2020 |
36İzleyin | CVE-2020-15240İstismar yok | Regression in JWT Signature Validationauth0 · omniauth-auth0 · CWE-287 | Kritik9,1 | — | %0,8 | 21 Eki 2020 |
35İzleyin | CVE-2020-15259İstismar yok | CSRF in Auth0 ad-ldap-connectorauth0 · ad\/ldap connector · CWE-352 | Yüksek8,8 | — | %1,0 | 6 Kas 2020 |
35İzleyin | CVE-2021-41246İstismar yok | Session fixation in express-openid-connectauth0 · express openid connect · CWE-384 | Yüksek8,8 | — | %0,9 | 9 Ara 2021 |
35İzleyin | CVE-2020-5391İstismar yok | Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.auth0 · wp-auth0 · CWE-352 | Yüksek8,8 | — | %0,8 | 1 Nis 2020 |
35İzleyin | CVE-2018-6874İstismar yok | CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.auth0 · auth0.js · CWE-352 | Yüksek8,8 | — | %0,7 | 4 Nis 2018 |
35İzleyin | CVE-2018-7307İstismar yok | The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.auth0 · auth0.js · CWE-352 | Yüksek8,8 | — | %0,5 | 6 Mar 2018 |
35İzleyin | CVE-2018-15121İstismar yok | An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.auth0 · aspnet · CWE-352 | Yüksek8,8 | — | %0,5 | 28 Ağu 2018 |
32İzleyin | CVE-2017-16897İstismar yok | A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.auth0 · passport-wsfed-saml2 · CWE-290 | Yüksek8,1 | — | %1,4 | 27 Ara 2017 |
32İzleyin | CVE-2022-23539İstismar yok | jsonwebtoken unrestricted key type could lead to legacy keys usageauth0 · jsonwebtoken · CWE-327 | Yüksek8,1 | — | %0,5 | 22 Ara 2022 |
30İzleyin | CVE-2020-15125İstismar yok | Authorization header is not sanitized in an error object in auth0auth0 · auth0.js · CWE-209 | Yüksek7,7 | — | %1,5 | 29 Tem 2020 |
30İzleyin | CVE-2017-17068İstismar yok | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.auth0 · auth0.js · CWE-200 | Yüksek7,5 | — | %1,4 | 6 Ara 2017 |
30İzleyin | CVE-2019-16929İstismar yok | Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tauth0 · auth0.net · CWE-287 | Yüksek7,5 | — | %0,9 | 8 Eki 2019 |
30İzleyin | CVE-2022-23505İstismar yok | Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authenticationauth0 · passport-wsfed-saml2 · CWE-287 | Yüksek7,5 | — | %0,8 | 13 Ara 2022 |
30İzleyin | CVE-2022-23540İstismar yok | jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()auth0 · jsonwebtoken · CWE-287 | Yüksek7,6 | — | %0,5 | 22 Ara 2022 |
30İzleyin | CVE-2025-68129İstismar yok | Auth0-PHP SDK has Improper Audience Validationauth0 · auth0-php · CWE-863 | Yüksek7,5 | — | %0,4 | 17 Ara 2025 |
30İzleyin | CVE-2025-65945Kavram kanıtı | auth0/node-jws improper HMAC signature verification vulnerabilityauth0 · node-jws · CWE-347 | Yüksek7,5 | — | %0,2 | 4 Ara 2025 |
29İzleyin | CVE-2019-13483İstismar yok | Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.auth0 · passport-sharepoint · CWE-345 | Yüksek7,3 | — | %0,6 | 25 Tem 2019 |
28İzleyin | CVE-2026-42280İstismar yok | Improper Permission Checking in Auth.js SDKauth0 · auth0.js · CWE-863 | Yüksek7,1 | — | %0,3 | 27 May 2026 |
- CVE-2015-923542Planlayın
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmet
KritikCVSS 9,8Kavram kanıtıEPSS %9auth0 · jsonwebtoken29 May 2018
- CVE-2020-794740Planlayın
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
KritikCVSS 9,8İstismar yokEPSS %3auth0 · login by auth01 Nis 2020
- CVE-2018-687340Planlayın
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.
KritikCVSS 9,8İstismar yokEPSS %2auth0 · auth0.js4 Nis 2018
- CVE-2019-764440Planlayın
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
KritikCVSS 9,8İstismar yokEPSS %2auth0 · auth0-wcf-service-jwt11 Nis 2019
- CVE-2026-3423639İzleyin
Auth0 PHP SDK Insufficient Entropy in Cookie Encryption
KritikCVSS 9,8İstismar yokEPSS %0auth0 · auth0-php1 Nis 2026
- CVE-2020-794836İzleyin
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress.
YüksekCVSS 8,8İstismar yokEPSS %2auth0 · login by auth01 Nis 2020
- CVE-2020-1508436İzleyin
Authorization bypass in express-jwt
KritikCVSS 9,1İstismar yokEPSS %1auth0 · express-jwt30 Haz 2020
- CVE-2020-1524036İzleyin
Regression in JWT Signature Validation
KritikCVSS 9,1İstismar yokEPSS %1auth0 · omniauth-auth021 Eki 2020
- CVE-2020-1525935İzleyin
CSRF in Auth0 ad-ldap-connector
YüksekCVSS 8,8İstismar yokEPSS %1auth0 · ad\/ldap connector6 Kas 2020
- CVE-2021-4124635İzleyin
Session fixation in express-openid-connect
YüksekCVSS 8,8İstismar yokEPSS %1auth0 · express openid connect9 Ara 2021
- CVE-2020-539135İzleyin
Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain field.
YüksekCVSS 8,8İstismar yokEPSS %1auth0 · wp-auth01 Nis 2020
- CVE-2018-687435İzleyin
CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.
YüksekCVSS 8,8İstismar yokEPSS %1auth0 · auth0.js4 Nis 2018
- CVE-2018-730735İzleyin
The Auth0 Auth0.js library before 9.3 has CSRF because it mishandles the case where the authorization response lacks the state parameter.
YüksekCVSS 8,8İstismar yokEPSS %1auth0 · auth0.js6 Mar 2018
- CVE-2018-1512135İzleyin
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin.
YüksekCVSS 8,8İstismar yokEPSS %0auth0 · aspnet28 Ağu 2018
- CVE-2017-1689732İzleyin
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5.
YüksekCVSS 8,1İstismar yokEPSS %1auth0 · passport-wsfed-saml227 Ara 2017
- CVE-2022-2353932İzleyin
jsonwebtoken unrestricted key type could lead to legacy keys usage
YüksekCVSS 8,1İstismar yokEPSS %0auth0 · jsonwebtoken22 Ara 2022
- CVE-2020-1512530İzleyin
Authorization header is not sanitized in an error object in auth0
YüksekCVSS 7,7İstismar yokEPSS %2auth0 · auth0.js29 Tem 2020
- CVE-2017-1706830İzleyin
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12.
YüksekCVSS 7,5İstismar yokEPSS %1auth0 · auth0.js6 Ara 2017
- CVE-2019-1692930İzleyin
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID t
YüksekCVSS 7,5İstismar yokEPSS %1auth0 · auth0.net8 Eki 2019
- CVE-2022-2350530İzleyin
Passport-wsfed-saml2 vulnerable to Authentication Bypass for WSFed authentication
YüksekCVSS 7,5İstismar yokEPSS %1auth0 · passport-wsfed-saml213 Ara 2022
- CVE-2022-2354030İzleyin
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
YüksekCVSS 7,6İstismar yokEPSS %1auth0 · jsonwebtoken22 Ara 2022
- CVE-2025-6812930İzleyin
Auth0-PHP SDK has Improper Audience Validation
YüksekCVSS 7,5İstismar yokEPSS %0auth0 · auth0-php17 Ara 2025
- CVE-2025-6594530İzleyin
auth0/node-jws improper HMAC signature verification vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %0auth0 · node-jws4 Ara 2025
- CVE-2019-1348329İzleyin
Auth0 Passport-SharePoint before 0.4.0 does not validate the JWT signature of an Access Token before processing.
YüksekCVSS 7,3İstismar yokEPSS %1auth0 · passport-sharepoint25 Tem 2019
- CVE-2026-4228028İzleyin
Improper Permission Checking in Auth.js SDK
YüksekCVSS 7,1İstismar yokEPSS %0auth0 · auth0.js27 May 2026