VDB
Sign up
HIGH7.5

GHSA-3rpr-mg43-xhq4

auth0-js Privilege Escalation Vulnerability

Quick fix

GHSA-3rpr-mg43-xhq4 — auth0-js: upgrade to the fixed version with the command below.

npm install auth0-js@8.12.0

Details

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with `auth0.popup.callback()`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/auth0-js
Introduced in: 0Fixed in: 8.12.0
Fixnpm install auth0-js@8.12.0

References