PT-2020-14205 · Auth0 · Auth0

Osdiab

·

Published

2020-07-29

·

Updated

2021-04-28

·

CVE-2020-15125

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions auth0 versions prior to 2.27.1
Description The issue arises from the lack of sanitization of the Authorization header key in the error object, potentially exposing a bearer token when a request to the Auth0 management API fails. This affects users of the auth0 npm package who are using a Machine to Machine application authorized to use Auth0's management API.
Recommendations For versions prior to 2.27.1, upgrade to version 2.27.1 to resolve the issue. As a temporary workaround, consider restricting access to the Authorization header to minimize the risk of exploitation.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15125
GHSA-5JPF-PJ32-XX53

Affected Products

Auth0