Vulnerabilities (CVE)

Filtered by vendor Auth0 Subscribe
Filtered by product Angular-jwt
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-11537 1 Auth0 1 Angular-jwt 2024-02-28 4.3 MEDIUM 6.5 MEDIUM
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.