Описание
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:auth0:aspnet:-:*:*:*:*:*:*:*
cpe:2.3:a:auth0:aspnet-owin:-:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00149
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery
EPSS
Процентиль: 36%
0.00149
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-352