CVE-2018-6873
04.04.2018, 17:29
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.Enginsight
Vendor | Product | Version |
---|---|---|
auth0 | auth0.js | 𝑥 ≤ 8.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration