Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9m8-9xxp-q492

Опубликовано: 04 июн. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

Auth0-PHP SDK Deserialization of Untrusted Data vulnerability

Overview The Auth0 PHP SDK contains a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data.

Am I Affected? You are affected by this vulnerability if you meet the following preconditions:

  1. Applications using the Auth0-PHP SDK, versions between 8.0.0-BETA3 to 8.3.0.
  2. Applications using the following SDKs that rely on the Auth0-PHP SDK versions between 8.0.0-BETA3 to 8.3.0: a. Auth0/symfony, b. Auth0/laravel-auth0, c. Auth0/wordpress.

Fix Upgrade Auth0/Auth0-PHP to 8.3.1.

Acknowledgement Okta would like to thank Andreas Forsblom for discovering this vulnerability.

Пакеты

Наименование

auth0/auth0-php

composer
Затронутые версииВерсия исправления

>= 8.0.0-BETA3, < 8.3.1

8.3.1

EPSS

Процентиль: 22%
0.00071
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-502

Связанные уязвимости

nvd
8 месяцев назад

Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. Versions 8.0.0-BETA3 prior to 8.3.1 contain a vulnerability due to insecure deserialization of cookie data. If exploited, since SDKs process cookie content without prior authentication, a threat actor could send a specially crafted cookie containing malicious serialized data. Applications using the Auth0-PHP SDK are affected, as are applications using the Auth0/symfony, Auth0/laravel-auth0, or Auth0/wordpress SDKs, because those SDKsrely on the Auth0-PHP SDK versions from 8.0.0-BETA3 until 8.14.0. Version 8.3.1 contains a patch for the issue.

EPSS

Процентиль: 22%
0.00071
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-502