CVE-2020-15125
Summary
| CVE | CVE-2020-15125 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-29 17:15:00 UTC |
| Updated | 2021-04-28 17:08:00 UTC |
| Description | In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API |
Risk And Classification
Problem Types: CWE-209
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sanitize Headers on Errors by jimmyjames · Pull Request #507 · auth0/node-auth0 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Sanitize Headers on Errors by jimmyjames · Pull Request #507 · auth0/node-auth0 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| GitHub - auth0/node-auth0 at v2.27.1 | MISC | github.com | Release Notes, Third Party Advisory |
| Authorization header is not sanitized in an error object · Advisory · auth0/node-auth0 · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983193 Nodejs (npm) Security Update for auth0 (GHSA-5jpf-pj32-xx53)