Description
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-11537
Related Vulnerabilities
CVE-2019-0201 Vulnerability in maven package org.apache.zookeeper:zookeeper
CVE-2023-1428 Vulnerability in maven package io.grpc:grpc-protobuf
CVE-2022-48285 Vulnerability in maven package org.webjars.npm:jszip
CVE-2021-4307 Vulnerability in npm package baobab
CVE-2023-29016 Vulnerability in maven package io.goobi.viewer:viewer-core