Vulnerabilities/

Auth0 angular-jwt misinterprets allowlist as regex

Severity:
Medium

Description

Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain allowlist filter via a crafted domain.

Recommendation

Update the angular-jwt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
angular-jwt
Anything's wrong? Let us know Last updated on October 19, 2023

This issue is available in SmartScanner Professional

See Pricing