CVE-2018-6873
EUVD-2018-1861904.04.2018, 17:29
The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| auth0 | auth0.js | 𝑥 ≤ 8.10.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration