VDB
Sign up
LOW3.3

GHSA-9mh6-g99m-ppcw

auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import

Quick fix

GHSA-9mh6-g99m-ppcw — auth0/auth0-php: upgrade to the fixed version with the command below.

composer require auth0/auth0-php:^8.17.0

Details

### Overview In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.

### Am I affected? You are affected by this vulnerability if you meet the following preconditions: 1. Applications using the Auth0-PHP SDK, versions between v3.3.0 and v8.16.0, or 2. Applications using the following SDKs that rely on the Auth0-PHP SDK versions between v3.3.0 and v8.16.0: a. Auth0/symfony, b. Auth0/laravel-auth0, c. Auth0/wordpress.

### Fix Upgrade Auth0/Auth0-PHP to version 8.17.0 or greater.

### Acknowledgement Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/auth0/auth0-php
Introduced in: 3.3.0Fixed in: 8.17.0
Fixcomposer require auth0/auth0-php:^8.17.0

References