Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-46345

Опубликовано: 01 мая 2025
Источник: nvd
EPSS Низкий

Описание

Auth0 Account Link Extension is an extension aimed to help link accounts easily. Versions 2.3.4 to 2.6.6 do not verify the signature of the provided JWT. This allows the user the ability to supply a forged token and the potential to access user information without proper authorization. This issue has been patched in versions 2.6.7, 2.7.0, and 3.0.0. It is recommended to upgrade to version 3.0.0 or greater.

EPSS

Процентиль: 24%
0.00082
Низкий

Дефекты

CWE-290

EPSS

Процентиль: 24%
0.00082
Низкий

Дефекты

CWE-290