VDB
Sign up
HIGH7.7

GHSA-5jpf-pj32-xx53

Authorization header is not sanitized in an error object in auth0

Quick fix

GHSA-5jpf-pj32-xx53 — auth0: upgrade to the fixed version with the command below.

npm install auth0@2.27.1

Details

### Overview Versions before and including `2.27.0` use a block list of specific keys that should be sanitized from the request object contained in the error object. When a request to Auth0 management API fails, the key for `Authorization` header is not sanitized and the `Authorization` header value can be logged exposing a bearer token.

### Am I affected? You are affected by this vulnerability if all of the following conditions apply:

- You are using `auth0` npm package - You are using a Machine to Machine application authorized to use Auth0's management API https://auth0.com/docs/flows/concepts/client-credentials

### How to fix that? Upgrade to version `2.27.1`

### Will this update impact my users? The fix provided in patch will not affect your users.

### Credit http://github.com/osdiab

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/auth0
Introduced in: 0Fixed in: 2.27.1
Fixnpm install auth0@2.27.1

References