Количество 2
Количество 2
CVE-2018-11537
больше 7 лет назад
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
CVSS3: 6.5
EPSS: Низкий
GHSA-vm2p-f5j4-mj6g
больше 3 лет назад
Auth0 angular-jwt misinterprets allowlist as regex
CVSS3: 6.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-11537 Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain. | CVSS3: 6.5 | 0% Низкий | больше 7 лет назад | |
GHSA-vm2p-f5j4-mj6g Auth0 angular-jwt misinterprets allowlist as regex | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу
20