QID 981636
QID 981636: Dotnet (nuget) Security Update for Auth0.AuthenticationApi (GHSA-c9cg-q8r2-xvjq)
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c9cg-q8r2-xvjq for updates pertaining to this vulnerability.
Vendor References
- GHSA-c9cg-q8r2-xvjq -
github.com/advisories/GHSA-c9cg-q8r2-xvjq
CVEs related to QID 981636
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c9cg-q8r2-xvjq | Auth0.AuthenticationApi |
|