Auth0.js
cpe:2.3:a:auth0:auth0.js:*:*:*:*:*:*:*
- >= 8.11.0, <= 9.32.0
A vulnerability exists in the Auth0.js SDK, specifically in versions 8.11.0 prior to 9.32.0. Under certain conditions, the SDK may incorrectly disclose user profile information by using a valid access token in conjunction with a specially crafted invalid ID token. This issue arises in applications that depend on access control rules defined in Auth0 Actions.
Exploitation of this vulnerability could lead to unauthorized access to user profile information.
Users can upgrade to Auth0.js version 10.0.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.