Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
References
Link | Resource |
---|---|
https://auth0.com/docs/security/bulletins/cve-2018-11537 | Patch Vendor Advisory |
Configurations
Information
Published : 2018-06-19 12:29
Updated : 2018-08-23 07:17
NVD link : CVE-2018-11537
Mitre link : CVE-2018-11537
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
auth0
- angular-jwt