HIGH7.5
GHSA-3rpr-mg43-xhq4
auth0-js Privilege Escalation Vulnerability
Quick fix
GHSA-3rpr-mg43-xhq4 — auth0-js: upgrade to the fixed version with the command below.
npm install auth0-js@8.12.0Details
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with `auth0.popup.callback()`.
Are you affected?
Enter the version of the package you're using.