Количество 2
Количество 2
CVE-2018-15121
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations.
GHSA-mmhr-3jr7-qj2p
Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-15121 An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applications vulnerable to CSRF attacks during authentication and authorization operations. | CVSS3: 8.8 | 0% Низкий | больше 7 лет назад | |
GHSA-mmhr-3jr7-qj2p Auth0-ASPNET and Auth0-ASPNET-Owin vulnerable to Cross-Site Request Forgery | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу