VYPR

Lock

by Auth0

Source repositories

CVEs (4)

  • CVE-2021-32641HigJun 4, 2021
    risk 0.46cvss 8.1epss 0.02

    auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflected XSS. An attacker can execute arbitrary code when the library's `flashMessage` feature is utilized and user input or data from URL parameters is incorporated…

  • CVE-2020-15119MedAug 20, 2020
    risk 0.35cvss 6.4epss 0.01

    In auth0-lock versions before and including 11.25.1, dangerouslySetInnerHTML is used to update the DOM. When dangerouslySetInnerHTML is used, the application and its users might be exposed to cross-site scripting (XSS) attacks.

  • CVE-2022-29172MedMay 5, 2022
    risk 0.33cvss 6.1epss 0.01

    Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Directory, LDAP, Google Apps, and Salesforce. In versions before `11.33.0`, when the “additional signup fields” feature [is configured](https://github.com/auth0/loc…

  • CVE-2019-20174MedFeb 3, 2020
    risk 0.33cvss 6.1epss 0.01

    Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.