Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
References
Link | Resource |
---|---|
https://auth0.com/docs/security/bulletins/cve-2018-11537 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2018-06-19 19:29
Updated : 2024-02-28 16:25
NVD link : CVE-2018-11537
Mitre link : CVE-2018-11537
CVE.ORG link : CVE-2018-11537
JSON object : View
Products Affected
auth0
- angular-jwt
CWE
CWE-20
Improper Input Validation