PT-2022-2605 · Auth0 · Auth0

Evansimspublished

·

Published

2022-05-05

·

Updated

2023-03-01

·

CVE-2022-29172

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Auth0 versions prior to 11.33.0
Description The issue is related to the "additional signup fields" feature in Auth0, where a malicious actor can inject invalidated HTML code into these fields, which is then stored in the service user metdata payload using the name property. This can allow an actor to craft a malicious link by injecting HTML, which is then rendered as the recipient's name within the delivered email template.
Recommendations For versions prior to 11.33.0, upgrade to version 11.33.0 to fix the issue. As a temporary workaround, consider restricting the use of the "additional signup fields" feature until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-03063
CVE-2022-29172
GHSA-7WW6-75FJ-JCJ7

Affected Products

Auth0