High severity7.7NVD Advisory· Published Jul 29, 2020· Updated Jun 17, 2026
CVE-2020-15125
CVE-2020-15125
Description
In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0's management API
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
auth0npm | < 2.27.1 | 2.27.1 |
Affected products
3- Range: < 2.27.1
Patches
Vulnerability mechanics
References
6- github.com/auth0/node-auth0/pull/507nvdPatchThird Party AdvisoryWEB
- github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3cnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5jpf-pj32-xx53ghsaADVISORY
- github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53nvdThird Party AdvisoryWEB
- github.com/auth0/node-auth0/tree/v2.27.1nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15125ghsaADVISORY
News mentions
0No linked articles in our index yet.