CRITICAL🇵🇱 Wersja polska

CVE-2019-7644

CVSS 9.8v3.0pub. 2019-04-11upd. 2024-11-21

Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Auth0 Wcf Service Jwt

    APP
    Auth0
    < 1.0.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-7947CRITICAL9.8PL ✓same vendor

CSV injection w pluginie Login by Auth0 dla WordPress (przed 4.0.0)

CVE-2015-9235CRITICAL9.8PL ✓same vendor

Pominięcie weryfikacji podpisu JWT w module jsonwebtoken (algorithm confusion)

CVE-2018-6873CRITICAL9.8PL ✓same vendor

Auth0 auth0.js — brak walidacji audience w JWT umożliwia privilege escalation

CVE-2026-42280HIGH7.1same vendor

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, t...

CVE-2026-34236HIGH8.2same vendor

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19...