Information Exposure Affecting auth0 package, versions <2.27.1
Threat Intelligence
EPSS
0.09% (41st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-AUTH0-596476
- published 30 Jul 2020
- disclosed 30 Jul 2020
- credit Unknown
Introduced: 30 Jul 2020
CVE-2020-15125 Open this link in a new tabHow to fix?
Upgrade auth0
to version 2.27.1 or higher.
Overview
auth0 is a SDK for Auth0 API v2
Affected versions of this package are vulnerable to Information Exposure. A DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token.
References
CVSS Scores
version 3.1