Vulnerabilities/

Cross-Site Request Forgery (CSRF) in Auth0

Severity:
High

Description

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

Recommendation

Update the auth0-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
auth0-js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing