Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15125 – In auth0 (npm package) versions before 2.27.1, a DenyList of specific key

In auth0 (npm package) versions before 2.27.1, a DenyList of specific keys that should be sanitized from the request object contained in the error object is used. The key for Authorization header is not sanitized and in certain cases the Authorization header value can be logged exposing a bearer token. You are affected by this vulnerability if you are using the auth0 npm package, and you are using a Machine to Machine application authorized to use Auth0’s management API

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15125

Reference (s):

  • https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53
  • URL: https://github.com/auth0/node-auth0/security/advisories/GHSA-5jpf-pj32-xx53
  • https://github.com/auth0/node-auth0/pull/507
  • URL: https://github.com/auth0/node-auth0/pull/507
  • https://github.com/auth0/node-auth0/pull/507/commits/62ca61b3348ec8e74d7d00358661af1a8bc98a3c
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser