CVE-2020-5263 Information
Feb 14, 2021
cve
Description
auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error the error object returned by the library contains the original request of the user which may include the plaintext password the user entered. If the error object is exposed or logged without modification the application risks password exposure. This is fixed in version 9.12.3
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/auth0/auth0.js/commit/355ca749b229fb93142f0b3978399b248d710828 https://github.com/auth0/auth0.js/security/advisories/GHSA-prfq-f66g-43mp
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.9
Share on: