QID 983762

QID 983762: Dotnet (nuget) Security Update for Auth0-WCF-Service-JWT (GHSA-qpvx-gpqm-g98j)

Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an arbitrary JWT token that will be accepted by the vulnerable application.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-qpvx-gpqm-g98j for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983762

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qpvx-gpqm-g98j Auth0-WCF-Service-JWT URL Logo github.com/advisories/GHSA-qpvx-gpqm-g98j