VYPR
High severity7.5NVD Advisory· Published Dec 6, 2017· Updated May 13, 2026

CVE-2017-17068

CVE-2017-17068

Description

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application uses a popup callback page with auth0.popup.callback().

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
auth0-jsnpm
< 8.12.08.12.0

Affected products

1
  • cpe:2.3:a:auth0:auth0.js:*:*:*:*:*:*:*:*
    Range: <8.12

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.