VYPR

Vendor CVEs

Auth0

All CVEs

54 total · sorted by risk
  • CVE-2021-41246MedDec 9, 2021
    risk 0.23cvss 4.6epss 0.01

    Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions before and including `2.5.1` do not regenerate the session id and session cookie when user logs in. This behavior opens up the application to various session…

  • CVE-2022-23505MedDec 13, 2022
    risk 0.00cvss 5.3epss 0.01

    Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the…

  • CVE-2020-15259HigNov 6, 2020
    risk 0.00cvss 8.1epss 0.01

    ad-ldap-connector's admin panel before version 5.0.13 does not provide csrf protection, which when exploited may result in remote code execution or confidential data loss. CSRF exploits may occur if the user visits a malicious page containing CSRF payload on the same machine…

  • CVE-2020-15125HigJul 29, 2020
    risk 0.00cvss 7.7epss 0.02

    In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged…

Page 2 of 2