Описание
laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
Overview
In applications built with the Auth0-PHP SDK, the Bulk User Import endpoint does not validate the file path wrapper or value. Without proper validation, affected applications may accept arbitrary file paths or URLs.
Am I affected?
You are affected by this vulnerability if you meet the following preconditions:
- Applications using the Auth0 laravel-auth0 SDK with version between 4.0.0 and 7.18.0,
- Auth0 laravel-auth0 SDK uses the Auth0-PHP SDK with versions between 3.3.0 and 8.16.0.
Fix
Upgrade Auth0 laravel-auth0 SDK to version 7.19.0 or greater.
Acknowledgement
Okta would like to thank Mohamed Amine Saidani (pwni) for discovering this vulnerability.
Пакеты
Наименование
auth0/login
composer
Затронутые версииВерсия исправления
>= 4.0.0, <= 7.18.0
7.19.0
3.3 Low
CVSS3
Дефекты
CWE-434
3.3 Low
CVSS3
Дефекты
CWE-434