Description
Auth0 angular-jwt before 0.1.10 treats whiteListedDomains entries as regular expressions, which allows remote attackers with knowledge of the jwtInterceptorProvider.whiteListedDomains setting to bypass the domain whitelist filter via a crafted domain.
Remediation
References
https://auth0.com/docs/security/bulletins/cve-2018-11537
Related Vulnerabilities
CVE-2017-3589 Vulnerability in maven package mysql:mysql-connector-java
CVE-2023-50765 Vulnerability in maven package org.jenkins-ci.plugins:scriptler
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2023-50768 Vulnerability in maven package org.sonatype.nexus.ci:nexus-jenkins-plugin
CVE-2023-25158 Vulnerability in maven package org.geotools.jdbc:gt-jdbc-oracle